Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
titanium98118
New Contributor II

IPV6 FQDN objects can't be added to SD-WAN rules

Hi,

 

I find that IPV6 SD-WAN rules are unable to add IPV6 FQDN objects.

Was this by-design? Or a bug?

Device: fortigate 60e

OS: 7.4.7

 

config firewall address6
    edit "speed.cloudflare.com"
        set uuid 3e275afe-e74f-51ef-ba51-85ac2c2767bd
        set type fqdn
        set fqdn "speed.cloudflare.com"
    next
end

 

 

screenshot.png

7 REPLIES 7
Jean-Philippe_P
Moderator
Moderator

Hello titanium98118, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again,

 

Please tell me if this works:

 

To add IPv6 FQDN objects to SD-WAN rules with FortiGate 60E running v7.4.7, follow these steps:

 

  1. Create an IPv6 FQDN Address Object:

   - Go to Policy & Objects -> Addresses -> Addresses.

   - Select Create New and select Address.

   - Choose IPv6 as the Address Type.

   - Enter the FQDN address in the format: ‘*.example.com’.

   - Save the address object.

 

  1. Configure SD-WAN Rule with the IPv6 FQDN Address Object:

   - Go to Policy & Objects -> SD-WAN Rules.

   - Select Create New to add a new rule.

   - Set the Source and Destination as needed.

   - Under Destination Address, select the IPv6 FQDN address object created in step 1.

   - Configure other settings like Service, Members, and Action accordingly.

   - Save the SD-WAN rule.

 

By following these steps, you can add IPv6 FQDN objects to SD-WAN rules on your FortiGate 60E running v7.4.7.

Jean-Philippe - Fortinet Community Team
titanium98118

Hi Philippe,

It's still unable to select FQDN object from IPv6 SD-WAN rules.

2.png1.png

rmreddy
Staff
Staff

Hi,

looks like it is a bug in v7.4.7, please reach TAC.
In v7.6.x able to create.

titanium98118

TAC answered,

It may not a bug. On 7.4.7 version, sdwan rule not support IPv6 FQDN,lt only support IPv6 subnet address.

Jean-Philippe_P
Moderator
Moderator

Thanks titanium98118 for letting us know!

 

Have a great day!

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors