Created on
10-11-2023
10:09 PM
Edited on
06-25-2024
04:55 PM
By
ssanga
Description |
This article describes that in the Web GUI under Policy & Objects -> Addresses, all FQDN Address Objects may show unresolved 'Unresolved FQDN' when highlighted except for the wildcard FQDNs on v7.2.6 and v7.2.7 (no such issue on v7.2.5). |
Scope | FortiGate v7.2.6, v7.2.7. |
Solution |
The issue is caused by a bug/regression introduced in v7.2.6 and v7.2.7, where the FortiGate Web GUI is not correctly displaying the list of IP addresses that an FQDN resolves to.
When checking from the CLI, the FortiGate will show the list of resolved IPs per FQDN Address object, indicating that it is resolving the FQDNs correctly. The following commands can be used to check the FQDNs and their resolved IP addresses:
diagnose firewall fqdn list-ip
fqdn_u 0x116330d7 gmail.com: type:(1) ID(218) count(1) generation(653) data_len:13 flag: 1
The following are some final points regarding this bug:
This issue is fixed in FortiOS v7.2.8 and v7.4.4. |