Hello,
Regarding the fortigate webfilter, I can use wildcards, but does it include multiple subdomains?
If I use wildcards, can I have any number of subdomains with a singleasterisk?
example:
Domains defined with wildcards : *.example.com
included? :aaa.example.com, bbb.aaa.example.com, ccc.bbb.aaa.example.com
Hello,@dingjerry_FTNT
Thank you for your prompt reply.
Here,
['*.' will also match any subdomains as well as the base domain.]
which means that any number of subdomains can be included in the wildcard, right?
Hi, not a definite answer as I did not check all possible scenarios - but I did experimenting with the number of subdomains (some 2 years ago, guess FortiOS 7.0.x) and FGT was checking up to 11 subdomains, after that it ignored if I added more subdomains.
Again, not 100% verified - it may be those 11 subdomains exceeded allowed FQDN length (255 bytes/chars) or something else.
Hi @willbase ,
As far as I know, there is no number limit for a wildcard to be matched.
And *.domain.com will match subdomain.domain.com as well as subdomaindomain.com.
Hello,@dingjerry_FTNT
Thank you.
I understand that there is no limit to the number of subdomains.
So any character before the asterisk(*), even if it doesn't have a dot(.), is included in the wildcard.
Correct, as it stated in the doc:
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.