Hello everybody.
I guess I' m facing this issue too, but with some slight differences. Thus I' m asking for help over here...
After Upgrading from MR2 (don' t remember which Patch-Level) to MR3 Patch7, 2 Policies based on FQDN-Objects stopped working.
The policies are identical, the only difference is that they have different destination interfaces: once on WAN1, once on WAN2.
Now, to the policies themselves: as source I have an Address Group made of one Address Object defined as an IP and a couple of Address Objects defined as FQDNs. Those FQDNs relate to the internal (LAN) domain: hst0027.domain.local is an example.
As I was reading through this thread, I decided to remove the IP-based Object from the Address Group and split up the policy by using 2 objects: the Address Group (now made only of FQDNs) and the IP-based Firewall Address Object.
Still, the Policy is not working, not being hit.
If I instead just put one single member of the Address Group into that policy (as source), the policy is working.
I checked wether the Fortigate is able to correctly solve hostnames and it does (diag firewall fqdn list - diag test app dnsproxy).
What should the next steps look like?
Thanks and kind regards,
F.