FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
WinterSnowYap
Article Id 248390

 

Description

Wildcard FQDN shows an unresolved IP address and the user is unable to access to the URLs if that applied Wildcard FQDN at firewall policy.

 

This article provides a solution to resolve the IP address for Wildcard FQDN. 

Scope FortiGate.
Solution

Issue scenario:

'*.playstation.com' is used as an example for Wildcard FQDN with the targeted URL included:

- www.playstation.com

- store.playstation.com

 

After creating a Wildcard FQDN, it will show an Unresolved FQDN when hovered.

 

KenYap_0-1678254096476.png

 

KenYap_2-1678254485407.png

 

If this Wildcard FQDN is applied to the policy, it will not function properly as this Wildcard FQDN does not have any IP address information for the related URLs.

 

Solution:

Below is the guide to resolve the IP address for Wildcard FQDN that was created in FortiGate.

 

1) A policy with DNS service is required to create and put on top of the Wildcard FQDN address policy.

 

KenYap_3-1678254760549.png

 

When any URLs are related to Wildcard FQDN are reached, it will hit the above DNS policy 1st and the IP address of the URLs will be recorded inside Wildcard FQDN.

 

KenYap_4-1678255025082.png

 

After access to the related URLs, hover again on the Wildcard FQDN, this time it will show the IP address information.


If the issue still persists, contact Fortinet Support.


To contact support by phone:
http://www.fortinet.com/support/contact_support.html