Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
saim
New Contributor

FQDN address is not working

Hi, I have fortigate 1000A I am using version v4.0,build0521,120313 (MR3 Patch 6). I have added in address imap.gmail.com but its not working. I have checked everything is fine as I give IP address it works. any idea.
Saim.... FortiGate 1000A (v4.0,build0535,120511 (MR3 Patch 7)) FortiAnalyzer-800B (v4.0,build0654 (MR3 Patch 3))
Saim.... FortiGate 1000A (v4.0,build0535,120511 (MR3 Patch 7)) FortiAnalyzer-800B (v4.0,build0654 (MR3 Patch 3))
32 REPLIES 32
ede_pfau
SuperUser
SuperUser

do you see this as well?
 gate # diag firewall fqdn list 
 ...
 maps.google.com: ID(201) REF(2) ADDR(209.85.148.102)
 ADDR(209.85.148.139) ADDR(209.85.148.113)
 ADDR(209.85.148.138) ADDR(209.85.148.100)
 ADDR(209.85.148.101)
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
mEjdejBDG
New Contributor

Mentioned above server need to access only to this one URL maps.google.com, and nothing else. Of course, I have couple policies for those two interfaces. How can I print setting only for this policy? Sorry for my english ;)
mEjdejBDG
New Contributor

I see this:
List all FQDN: maps.google.com: ID(201) REF(2) ADDR(173.194.32.33) ADDR(173.194.32.35) ADDR(173.194.32.34) ADDR(173.194.32.46) ADDR(173.194.32.38) ADDR(173.194.32.40) ADDR(173.194.32.36) ADDR(173.194.32.39) ADDR(173.194.32.37) ADDR(173.194.32.32) ADDR(173.194.32.41)
ede_pfau
SuperUser
SuperUser

Never mind. Display the policy like this (here policy #36, get the right ID from GUI):
 gate # show firewall policy 36
 config firewall policy
     edit 36
         set srcintf " internal" 
         set dstintf " wan1" 
         set srcaddr " BEDV_LAN"              
         set dstaddr " maps"              
         set schedule " always" 
         set service " ANY"              
         set logtraffic enable
         set comments " test FQDN policy 2012-05-21" 
     next
 end
 
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
mEjdejBDG
New Contributor

config firewall policy
     edit 33
         set srcintf " switch" 
         set dstintf " port10" 
             set srcaddr " GIS serwer"              
             set dstaddr " Google maps"              
         set action accept
         set schedule " always" 
             set service " ANY"              
         set utm-status enable
         set logtraffic enable
         set av-profile " Uzytkownik AV" 
         set profile-protocol-options " default" 
         set nat enable
     next
 end
ede_pfau
SuperUser
SuperUser

a) what does the Traffic log say about your connection attempts? it must log something b) would you please create a new FQDN address with a single name like " maps" , and FQDN " maps.google.com" . It' s just a suspicion but there' s a blank in the address name.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
mEjdejBDG
New Contributor

a) There are some connections, but with 0B sent and recieved... b) It didn' t help...
ede_pfau
SuperUser
SuperUser

This is not easy to debug. Here is a work-around: I created a new address name " maps1" = 173.194.70.138 and put that into the policy. This works for me. If you try that and it does not work then we know it' s not the address...
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
mEjdejBDG
New Contributor

And You have responses from maps.google.com? I did it in the same way, ane when I pinging on the name, there' s no response. When on the IP - it works :| Something with DNS configuration? But what.. I' ve checked many times.
ede_pfau
SuperUser
SuperUser

I' ve got no problems with either the FQDN address or the numerical IP address. If you suspect DNS to be a problem then, if you enter ' nslookup maps.google.com' on the command line of a) a host in your LAN (or the server) b) the Fortigate, do you get the same IP addresses as with the ' diag firewall fqdn list' command?
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors