Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
willbase
New Contributor II

About wildcard specifications

Hello,

 

Regarding the fortigate webfilter, I can use wildcards, but does it include multiple subdomains?

If I use wildcards, can I have any number of subdomains with a singleasterisk?

 

example:

Domains defined with wildcards : *.example.com

included?              :aaa.example.com, bbb.aaa.example.com, ccc.bbb.aaa.example.com

 

8 REPLIES 8
dingjerry_FTNT
willbase

Hello,@dingjerry_FTNT

 

Thank you for your prompt reply. 

 

Here,

['*.' will also match any subdomains as well as the base domain.]

which means that any number of subdomains can be included in the wildcard, right?

Yurisk

Hi, not a definite answer as I did not check all possible scenarios - but I did experimenting with the number of subdomains (some 2 years ago, guess FortiOS 7.0.x) and FGT was checking up to 11 subdomains, after that it ignored if I added more subdomains. 

Again, not 100% verified - it may be those 11 subdomains exceeded allowed FQDN length (255 bytes/chars) or something else. 

https://yurisk.info
https://yurisk.info
willbase
New Contributor II

Hello,@Yurisk

 

Thank you for your prompt reply. 

I understand the content of your response.

I try it.

dingjerry_FTNT

Hi @willbase ,

 

As far as I know, there is no number limit for a wildcard to be matched.

 

And *.domain.com will match subdomain.domain.com as well as subdomaindomain.com.

Regards,

Jerry
willbase

Hello,@dingjerry_FTNT

 

Thank you.

I understand that there is no limit to the number of subdomains.

So any character before the asterisk(*), even if it doesn't have a dot(.), is included in the wildcard.

dingjerry_FTNT

Correct, as it stated in the doc:

 

  • In FortiOS v6.0.5 and later, entries beginning in '*.' will also match any subdomains as well as the base domain. For example, '*.fortinet.com' will match sub-domains of the URL 'support.fortinet.com', 'www.fortinet.com', and will also match 'fortinet.com'.
Regards,

Jerry
willbase

Hello,dingjerry_FTNT

 

Thank you for explaining it so courteously.

Understood.

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors