Yep. I' ve had v3.0 to beta test for a month now, and this is one one of the first things I put in a bug fix request for, only to find out that they don' t really think it' s a " bug" , but have actually designed it incorrectly.
One other negative side effect of this is that in addition to not being able to resolve external addresses for policy rules, it' s also not capable of resolving internal workstation addresses, so rules like allow LAN " userpc.domain.com" WAN " update.nai.com" any any won' t work, which means if you use DHCP, (which most of us do, as maintaining static address tables for hundreds of users is too cumbersome) you can' t create granular rules.
To me, this kind of defeats the purpose of having the feature in the first place.
Thought for the day:
Advertising (n): the science of arresting the human
intelligence for long enough to get money from it.
-- Stephen Leacock.