Description |
This article explains how to map domain IP addresses to wildcard FQDN objects when DNS traffic is encrypted. FortiOS supports wildcard FQDN objects for firewall policies, static routes, SD-WAN rules, and other configurations. However, for these objects to be mapped to the corresponding IP addresses, FortiGate must be able to see the DNS responses for the FQDNs belonging to the wildcard FQDN object domain. This is not possible when DNS traffic is encrypted.
FortiGate can map the correct IP addresses to the wildcard FQDN objects using Full SSL Inspection to decrypt the DNS traffic in this scenario. |
Scope | FortiGate. |
Solution |
To map domain IP addresses to wildcard FQDN objects when DNS traffic is encrypted, follow these steps:
config firewall policy
Since the session traffic will be handled by this rule, DNS queries and responses will be visible to FortiGate, allowing it to map the corresponding IP addresses.
Note:
|