Hello team,
I have an argument to share and would also like your opinion.
If I create a wildcard FQDN object *.pluto.com qwhen the client does dns traffic I also get sub domains resolved for example foo.pluto.com duck.pluto.com etc.
Now if by chance a subdomain is malevo this is resolved anyway and the fqdn wildcard object is updated with the malevoo ip. What advice can you give me to fix this problem? Or maybe it is not necessary if you configure other security profiles ad hoc?
Thanks
BR
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Luca
This can't be handled at object level, but at web filter or so.
So you can still use the same object but just add a web filter profile if it is for web access.
Hi Luca
In your case the wildcard object will contain the 3 FQDN with their IP address. Can you explain what is exactly the problem?
Hello @AEK ,
I meant if a malicious fqdn ip is resolved because for example if foo.pluto.com is a malicious subdomain this is resolved and the FQDN wildcard object is updated with the malicious ip address
BR
Hi Luca
This can't be handled at object level, but at web filter or so.
So you can still use the same object but just add a web filter profile if it is for web access.
Nothing can be done from FQDN resolution perspective. Instead you can Web Filter profile to block traffic going to malicious domains.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.