we are getting email alert for the Fqdn Refresh job failed on passive device
does passive device need to do the fqdn refresh?
Solved! Go to Solution.
I would say yes since if it needs to take over its up to date. Check which interface you are using for the 'Service Path', if it is not the management port, it will not be up on a passive device. Also it could be something else blocking the traffic?
Just a few thoughts.
As @Otakar.Klier mentioned really the default answer to this question would be yes. However, depending on what you're using FQDNs for and how vital they are in your configuration, a laps of an update could potentially be a non/small issue that is acceptable for your organization. A lot of people run into this on passive devices since they aren't using the management port, and in that case I would just say that you shouldn't use any FQDN objects in vital policies.
That being said, obviously giving the device a dedicated management interface has multiple advantages outside of just allowing FQDN refreshes while passive. If at all possible, I would really recommend that the firewall management port always have a connection and you don't rely on the service routes option.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!