Hi
We often use FQDN address object to allow traffic from LAN site to external resources.
But how about an external resource as an FQDN (multiple dynamic public address covered, as it is a cloud service).
Does it work, if we create a policy, with a VIP as destination, where the source is a FQDN object?
I can't find any official documentation for this a first draft
Yes this is possible.
The only thing you need to careful with is that the FortiGate needs to be able to correctly translate the FQDN. This is through the DNS configuration in the settings.
You might want to consider leveraging the ISDB if your cloud service is listed there. This will ensure all IP addresses and FQDNs associated with the service are captured.
Using FQDN resolution alone can sometime not catch all IP addresses associated with the service especially if they are doing a lot of round-robin type stuff. Sometime they can have many IPs listed but DNS resolvers may only resolve a few of them at a time.
You are right.
However in this case, the source Cloud resource is a custom build network-service. It's only that specific web resource that should be allowed access, and not the entire public cloud platform.
That's why I'd have to go with the FQDN address object as source.
And it's exactly the issue you are describing that I'm worries about.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.