Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RadioLontra
New Contributor

FQDN address using wildcards

Hi everybody, i' m tryin to permit access from some clients to the Microsoft update servers. I wanted to do it enabling a couple of addressess , like *.microsoft.com and *.windowsupdate.com, which should work easily, but Fortigate does not accept wildcards in FQDN names. Or, better, i can save the address with the wildcard but it does not work. Even the CLI does not offer any different feature Is there any way to work around this or a i have to add all the names in detail? Fortigate is 50B MR1 u1 mnay thanks GiBiT
5 REPLIES 5
Carl_Wallmark
Valued Contributor

instead of FQDN, create a local webfilter, that one supports wildcards,

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
RadioLontra
New Contributor

It' s not a matter of web filtering, navigation is blocked by a firewall policy which denies access to the external interface. I need to permit access for a group of ip or fqdn addresses..
billp
Contributor

As far as I know, it' s not possible to use wildcards in a FQDN.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
rwpatterson
Valued Contributor III

Use custom ratings. Works like a charm with licensed Fortiguard service.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
FortiRack_Eric
New Contributor III

The best way for doing this is to use local webfiltering: 1. Go to Web Filter > URL Filter. 2. Select Create New, or select an already available list. 3. Select Create New, to create an entry for each of the following exempt rules. o URL= .*update\.microsoft\.com.* Type= regex Action= exempt o URL= .*download\.windowsupdate\.com.* Type= regex Action =exempt o URL= .*\.microsoft\.com.* Type= regex Action =exempt By using an exempt rule, it also avoids that AV is performed on the downloads as this usually triggers the heuristics rule (flagged as suspicious) Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors