- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 Different FQDN with same resolved IP
Good day!
I hope you are all doing well, I just want to ask what are the possible solutions when we input 2 FQDN (one is malicious and 1 is legitimate) it resolved same IP addresses. the FQDN that tagged as malicious are blocked via deny policy. However the our client are having a problem accessing the legit FQDN because of the same IP.
the legit website are from Cloudflare. does cloudflare assigned same ip address to FQDNs?
Thank you!
Solved! Go to Solution.
- Labels:
-
FortiClient
-
FortiGate
-
FortiGate-VM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi FortiBen
I guess this is the case of shared hosting, i.e.: multiple domains behind the same IP.
If the users can't access the legit FQDN then try disable rating the IP address in the related web filter profile. That way only domain name will be rated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CloudFllare and any other CDN provider assign same the same IP address to thousands and millions of proxied domains. This is expected and is the normal behavior on such services.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi FortiBen
I guess this is the case of shared hosting, i.e.: multiple domains behind the same IP.
If the users can't access the legit FQDN then try disable rating the IP address in the related web filter profile. That way only domain name will be rated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good day!
Thank for your prompt response. We will try to recommend to disable the malicious FQDN via web filter and not via address object
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CloudFllare and any other CDN provider assign same the same IP address to thousands and millions of proxied domains. This is expected and is the normal behavior on such services.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I see.. I'm not familiar yet on the CDN side but I will look in to this. Thank you for your input!
