FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
WinterSnowYap
Article Id 248390

 

Description

This article describes a solution to resolve the IP address for Wildcard FQDN. 

Wildcard FQDN shows an unresolved IP address and the user is unable to access the URLs if that applied Wildcard FQDN at firewall policy.

Scope FortiGate.
Solution

Issue scenario:

'*.playstation.com' is used as an example for Wildcard FQDN with the targeted URL included:

- www.playstation.com

- store.playstation.com

 

After creating a Wildcard FQDN, it will show an Unresolved FQDN when hovered.

 

KenYap_0-1678254096476.png

 

KenYap_2-1678254485407.png

 

If this Wildcard FQDN is applied to the policy, it will not function properly as this Wildcard FQDN does not have any IP address information for the related URLs.

 

Solution: 

 

Note: For FQDN address objects to resolve, DNS queries must pass through the FortiGate. However, most browsers (Chrome, Firefox, Edge, etc) can encrypt the DNS traffic. When DNS traffic is encrypted, FortiGate will not be able to see encrypted DNS traffic unless 'Deep Packet Inspection' is enabled. Below is an example of secure DNS being enabled on Chrome. 

 

secure DNS.PNG

 

Below is the guide to resolving the IP address for Wildcard FQDN created on the FortiGate (when DNS traffic is not encrypted).

 

A policy with DNS service is required to be created and put on top of the Wildcard FQDN address policy.

 

KenYap_3-1678254760549.png

 

When any URLs related to Wildcard FQDN are reached, it will hit the above DNS policy 1st and the IP address of the URLs will be recorded inside Wildcard FQDN.

 

KenYap_4-1678255025082.png

 

After access to the related URLs, hover again on the Wildcard FQDN, this time it will show the IP address information.


If the issue persists, contact Fortinet Support.


To contact support by phone:
FortiCare Technical Support

 

Related articles: 

Technical Tip: Using a wildcard FQDN

Technical Tip: How to configure wildcard-FQDN custom and group

Technical Tip: Improve FQDN re-query interval on FortiGate

Technical Tip: FQDN based firewall policies are not working intermittently

Troubleshooting Tip: Wildcard FQDN addresses are not getting populated

Technical Tip: Use Internet Service Database vs FQDN