Created on
10-27-2025
02:40 AM
Edited on
10-27-2025
02:41 AM
By
Jean-Philippe_P
| Description |
This article describes the behavior where FortiGate DNS servers do not currently support wildcard (*) entries in secondary or shadow zones, or in DNS database forwarding configurations. Although wildcard entries can be stored, FortiGate does not interpret them dynamically, so queries for subdomains do not match the wildcard and may return an 'unknown host' response. |
| Scope | FortiOS v7.2, FortiOS v7.4, FortiOS v7.6. |
| Solution |
Administrators may try to use a wildcard domain in the FortiGate DNS database to:
Example scenario:
*.subdomain.local → 10.10.10.50
FortiGate DNS servers will store the wildcard record, but:
Verification:
Currently, this is considered a New Feature Request.
Workarounds:
config system dns-database
Queries for all subdomains of subdomain.local will be resolved correctly by the primary DNS server.
If only a few subdomains are required, manually add entries in the FortiGate DNS database:
config system dns-database
Note: It is not suitable for large or dynamic sets of subdomains. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.