Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bfig90
New Contributor III

TrendMicro Worry-Free Business Security Services (WFBS-SVC) not resolving in FortiGate

Dears,

 

TrendMicro Worry-Free Business Security Services (WFBS-SVC) provides different URLs used as reference for allowing listing from firewall or proxy server.

 

We created a rule in FortiGate using FQDN trendmicro.com but it is not working and it is resolving in only 1 IP. TrendMicro has more than 1. How we can resolve this ?

2025-01-30_15-37.png

 

Thank You 

 

 

1 Solution
vifi

Hi,
Yes, wildcard FQDN *.trendmicro.com will allow all subdomains of trendmicro.com.

View solution in original post

5 REPLIES 5
Hassan97wsh
Staff
Staff

Hi bfig90,

FortiGate uses the configured DNS servers in (Network>DNS) to resolve the IP of the given FQDN. If the DNS server only returns one IP, FortiGate will use that IP. FortiGate will also re-query the FQDN to get the latest IP.

If the IP changes in the answer, FortiGate will just simply replace it. This is not an issue if both FortiGate and the clients behind the FortiGate are configured with the same DNS server (i.e. same internal DNS server that will cache the IP of trendmicro.com) and receiving the same IP.

Please, refer to the community article below.

How to use the FQDN address object in For... - Fortinet Community

Hassan
TAC Engineer
bfig90
New Contributor III

Yes you right. My mistake. I want to resolve *.trendmicro.com in fortigate ? So it will allow all subdomains of trendmicro.com i.e: abc.trendmicro.com; xyz.trendmicro.com etc ? 

vifi

Hi,
Yes, wildcard FQDN *.trendmicro.com will allow all subdomains of trendmicro.com.

bfig90
New Contributor III

Thank You @vifi It worked

Hassan97wsh

Wildcard FQDN should cover all the subdomains, but you have to make sure the DNS queries sent by the client must pass through the FortiGate. Because unlike normal FQDNs, FortiGate does not activly sends queries for wildcard FQDNs. Instead, FortiGate inspects the DNS queries and replies passing through it.

 

Check the highlited part in this article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-wildcard-FQDN/ta-p/196118#:~:text=...).

Hassan
TAC Engineer
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors