Created on
03-17-2023
08:55 AM
Edited on
11-26-2025
08:55 AM
By
Stephen_G
| Description | This article describes how to allow routing using ISDB and FQDN objects for Microsoft update purposes. |
| Scope | FortiOS. |
| Solution |
Despite the possibility to control FortiGate routing only to a specific destination, such as for Microsoft update purposes, it is possible to use ISDB to facilitate the job rather than to define every IP individually.
However, it is important to be aware that not all IP addresses are possible to be listed in the FortiGuard ISDB (Internet Service Database).
Reason: The Microsoft Update service is hosted on CDN, which includes dynamically assigned IP addresses. The IP addresses change constantly and there is no publication of the IP addresses, meanwhile, ISDB is a static IP-based database service, which cannot handle dynamic IP addresses or FQDN directly.
It is suggested to use FQDN Address as a complimentary method to retrieve the latest IP addresses resolved from specific domains in the local environment.
To maintain connection to Microsoft, see this update page regularly.
How to add a complimentary config for this case:
Note 1: A valid firewall policy is required to handle the traffic correctly (not covered in this article).
Note 2: Starting in FortiOS 7.6.4, FQDN address groups can be added via the ISDB menu within the firewall policy configuration in the GUI. This functionality improves handling of dynamic or absent IP entries in the ISDB database. For further details, refer to GUI support for FQDN address groups within the ISDB 7.6.4 | Fortinet Document Library.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.