Created on 03-04-2024 09:04 AM Edited on 11-20-2024 07:16 AM By Jean-Philippe_P
Description | This article describes how to use the FQDN address object in FortiGate when the DNS resolution changes dynamically. |
Scope | All supported versions of FortiOS. |
Solution |
In cases where Websites with multiple servers have a load balanced between multiple locations, the DNS resolution can change dynamically. This may lead the DNS resolution of the user to not coincide with the DNS resolution of the FortiGate for a specific FQDN address.
In this case, the user will create a connection request with an IP that does not match the IP resolved by the Firewall for the same domain name and the connection will be dropped by the Firewall.
Below are the steps to configure the FortiGate as a DNS forwarder:
This will ensure that DNS resolution for the user and the FortiGate will be the same, resulting in incoming traffic from the user reliably matching the intended policy. This is covered under this article: Technical Tip: How to deal with FQDN with short DNS TTL |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.