Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fortifour
New Contributor

How to use a FQDN with more than 32 resolvable IP's?

Our current anti spam service provider uses a FQDN (delivery.antispamcloud.com) which currently resolves to more than 144 IP addresses (see https://noc.spamexperts.net/components/58c9068e8c48eb3e0f439674 for the full list, scroll down).

 

At first I used the FQDN but a lot of mail didn't came through. It turned out that the FQDN only resolved a maximum of 32 IP's (random), which seem to be a hard coded max value in every firmware version (5.4, 5.6, 6.0).

 

Currently I am subscribed to Spam Expert's IP update list to notify me of IP updates which I manually add as a address in my FortiGate 201E, afterwards add to the Address Group, which in turn is added as a IPV4 policy to allow only mail to our Exchance from those IP's.

 

It's very annoying to add new addresses every week because of this hardcoded max value. Is there another way to automate this or a workaround, except for changing anti spam provider?

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors