FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rmreddy
Staff
Staff
Article Id 342433
Description This article describes why Policy & objects -> Firewall policy network -> SD-WAN -> SD-WAN rule FQDN address objects show as unresolved.
Scope All supported FortiGate firmware.
Solution

While creating an IPv4 policy or an SD-WAN rule with FQDN address objects, the Policy & objects -> firewall policy, network -> SDWAN -> SDWAN rule section in the GUI will show them as unresolved even though, under address objects, the FQDN shows as resolved. 

 

sd-wan-9377327.png

 

Policy에서_unresolved표기.png

 

However, upon cross-verifying in the CLI, the address for the FQDN address objects created will list the IPs.

 

diagnose firewall fqdn list-ip

 

List all IP FQDN:


fqdn_u 0x10189820 prince.fg_1_auth: type:(1) ID(23) count(1) generation(2) data_len:13 flag: 1
ip list: (1 ip in total)
ip: 10.75.15.220
Total ip fqdn range blocks: 1.
Total ip fqdn addresses: 1.

fqdn_u 0x10189941 login.microsoftonline.com: type:(1) ID(33) count(11) generation(3868) data_len:143 flag: 1
ip list: (1 ip in total)
ip: 20.190.159.4
ip list: (1 ip in total)
ip: 20.190.160.20
ip list: (1 ip in total)
ip: 20.190.159.23
ip list: (1 ip in total)
ip: 40.126.31.67
ip list: (1 ip in total)
ip: 40.126.31.69
ip list: (1 ip in total)
ip: 40.126.31.71
ip list: (1 ip in total)
ip: 20.190.159.71
ip list: (1 ip in total)
ip: 20.190.159.73
ip list: (1 ip in total)
ip: 20.190.159.75
ip list: (1 ip in total)
ip: 40.126.32.136
ip list: (1 ip in total)
ip: 40.126.32.138
Total ip fqdn range blocks: 11.
Total ip fqdn addresses: 11.

 

This will not cause any impact in the firewall with the actual traffic for the FQDN object policy, as the FQDN is actually resolved: this is only a cosmetic bug in the GUI (bug ID: 1014584). This issue is fixed in v7.2.9, v7.4.4, and v7.6.0.