Created on
06-20-2025
03:40 AM
Edited on
06-26-2025
03:19 AM
By
Jean-Philippe_P
Description | This article describes the possible reasons why FortiGate may fail to synchronize wildcard FQDNs between HA FortiGates after the Secondary FortiGate is rebooted. |
Scope | FortiGate less than v7.6.4. |
Solution |
Even after the Secondary FortiGate is rebooted and completes synchronization with the Primary FortiGate, the resolved IP address of the 'wildcard FQDNs' may not be synchronized.
In contrast, regular (non-wildcard) FQDNs are properly synchronized between the Primary and Secondary FortiGate.
Additionally, when the Primary FortiGate resolves a new IP address for a previously unsynchronized wildcard FQDN, that FQDN will subsequently be included in the synchronization process.
To confirm whether synchronization is taking place, run the following command via the CLI and compare the results between the Primary and Secondary FortiGate:
diagnose test application dnsproxy 6
The following shows the FQDN synchronization status after the Secondary FortiGate has been rebooted and HA synchronization has completed.
FG2600F-Primary (global) # diagnose test application dnsproxy 6
Secondary:
FG2600F-Secondary (global) # diagnose test application dnsproxy 6
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.