Running 5.2.7 on a FGT60D and one of the sites that we programmatically retrieve data from has moved recently to Amazon's hosting service. Previously this traffic was permitted using the site FQDN, however as I understand it this can now resolve to a number of different IPs depending on server load etc. - data retrieval is failing periodically now.
What is the best practice for permitting traffic to a specific URL hosted in this way?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
In the absence of any responses I've been experimenting with Application Control and WebFilter policies without success.
I now have a ticket raised with Fortinet Support for assistance but would still appreciate any insights that the community could share.
You could use a FQDN style dans records in 5.4.x and with a short ttl, but ideally I would use a ipsec tunnel to the VPC
Ken
PCNSE
NSE
StrongSwan
emnoc wrote:You could use a FQDN style dans records in 5.4.x and with a short ttl, but ideally I would use a ipsec tunnel to the VPC
Ken
Thanks for responding however I'm not sure I understand; I should also have specified that we're using a FGT60 on 5.2.7 waiting on bugfixes for SSL DPI on inbound traffic before doing any firewall upgrades. The hosted site is an external resource (UK government) providing healthcare data that we make available to clients, so I'm not sure how the IPSec tunnel solution would apply?
Does 5.2.x permit the same FQDN approach?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.