Good day!
I hope you are all doing well, I just want to ask what are the possible solutions when we input 2 FQDN (one is malicious and 1 is legitimate) it resolved same IP addresses. the FQDN that tagged as malicious are blocked via deny policy. However the our client are having a problem accessing the legit FQDN because of the same IP.
the legit website are from Cloudflare. does cloudflare assigned same ip address to FQDNs?
Thank you!
Solved! Go to Solution.
Hi FortiBen
I guess this is the case of shared hosting, i.e.: multiple domains behind the same IP.
If the users can't access the legit FQDN then try disable rating the IP address in the related web filter profile. That way only domain name will be rated.
CloudFllare and any other CDN provider assign same the same IP address to thousands and millions of proxied domains. This is expected and is the normal behavior on such services.
Hi FortiBen
I guess this is the case of shared hosting, i.e.: multiple domains behind the same IP.
If the users can't access the legit FQDN then try disable rating the IP address in the related web filter profile. That way only domain name will be rated.
Good day!
Thank for your prompt response. We will try to recommend to disable the malicious FQDN via web filter and not via address object
CloudFllare and any other CDN provider assign same the same IP address to thousands and millions of proxied domains. This is expected and is the normal behavior on such services.
I see.. I'm not familiar yet on the CDN side but I will look in to this. Thank you for your input!
User | Count |
---|---|
2140 | |
1188 | |
770 | |
451 | |
347 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.