if there is no UDP DNS session helper enabled is, one issue could be the
FQDN Wildcard address failed to resolve when using it in Firewall
Policies as explained in the below
article.https://community.fortinet.com/t5/FortiGate/Technical-Tip-FQDN-Wildc...