Created on 10-11-2023 10:09 PM Edited on 06-25-2024 04:55 PM By ssanga
Description |
This article describes that in the Web GUI under Policy & Objects -> Addresses, all FQDN Address Objects may show unresolved 'Unresolved FQDN' when highlighted except for the wildcard FQDNs on v7.2.6 and v7.2.7 (no such issue on v7.2.5). |
Scope | FortiGate v7.2.6, v7.2.7. |
Solution |
The issue is caused by a bug/regression introduced in v7.2.6 and v7.2.7, where the FortiGate Web GUI is not correctly displaying the list of IP addresses that an FQDN resolves to.
When checking from the CLI, the FortiGate will show the list of resolved IPs per FQDN Address object, indicating that it is resolving the FQDNs correctly. The following commands can be used to check the FQDNs and their resolved IP addresses:
diagnose firewall fqdn list-ip
fqdn_u 0x116330d7 gmail.com: type:(1) ID(218) count(1) generation(653) data_len:13 flag: 1
The following are some final points regarding this bug:
This issue is fixed in FortiOS v7.2.8 and v7.4.4. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.