Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MrHoosFoos
New Contributor II

Allow policy for dynamic remote IP

We have an egress policy to allow traffic to a (partner) service hosted in AWS - thus the IP address of the remote server is dynamic.

In these scenarios, is there a way to create a policy object that can represent a dynamic lookup? Or how else might this be addressed on a Fortinet firewall... aside from a "looser" policy that only specifies source and protocol?

 

TIA!

1 Solution
jiahoong112
Staff
Staff

As your partner service aka Destination is a dynamic ip that's always changing, you can create a wildcard fqdn object and use that as the Destination Address of the firewall policy: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-wildcard-FQDN/ta-p/196118 

Alternatively, you can also use an AWS ISDB object as the destination object in the relevant firewall policy.

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**

View solution in original post

2 REPLIES 2
jiahoong112
Staff
Staff

As your partner service aka Destination is a dynamic ip that's always changing, you can create a wildcard fqdn object and use that as the Destination Address of the firewall policy: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-wildcard-FQDN/ta-p/196118 

Alternatively, you can also use an AWS ISDB object as the destination object in the relevant firewall policy.

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
MrHoosFoos

Thanks for the info! This is helpful!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors