Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
saim
New Contributor

FQDN address is not working

Hi, I have fortigate 1000A I am using version v4.0,build0521,120313 (MR3 Patch 6). I have added in address imap.gmail.com but its not working. I have checked everything is fine as I give IP address it works. any idea.
Saim.... FortiGate 1000A (v4.0,build0535,120511 (MR3 Patch 7)) FortiAnalyzer-800B (v4.0,build0654 (MR3 Patch 3))
Saim.... FortiGate 1000A (v4.0,build0535,120511 (MR3 Patch 7)) FortiAnalyzer-800B (v4.0,build0654 (MR3 Patch 3))
32 REPLIES 32
FlavioB
New Contributor III

ORIGINAL: RindlisE Hi, Try to use this Workaround. create a Group Object and put your Address Object in this Group. Use the Group Object in your Rule. Regards Erich
Hello Erich, ist your suggestion indeed working? For you? For somebody else? Do you mean to put ONE single object in this Group? Kind regards, F.
RH2
New Contributor II

Get rid of spaces in your address names. Fortinet IOS can do weird things when there is a space in the name.
FlavioB
New Contributor III

Hello everybody. I guess I' m facing this issue too, but with some slight differences. Thus I' m asking for help over here... After Upgrading from MR2 (don' t remember which Patch-Level) to MR3 Patch7, 2 Policies based on FQDN-Objects stopped working. The policies are identical, the only difference is that they have different destination interfaces: once on WAN1, once on WAN2. Now, to the policies themselves: as source I have an Address Group made of one Address Object defined as an IP and a couple of Address Objects defined as FQDNs. Those FQDNs relate to the internal (LAN) domain: hst0027.domain.local is an example. As I was reading through this thread, I decided to remove the IP-based Object from the Address Group and split up the policy by using 2 objects: the Address Group (now made only of FQDNs) and the IP-based Firewall Address Object. Still, the Policy is not working, not being hit. If I instead just put one single member of the Address Group into that policy (as source), the policy is working. I checked wether the Fortigate is able to correctly solve hostnames and it does (diag firewall fqdn list - diag test app dnsproxy). What should the next steps look like? Thanks and kind regards, F.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors