Fqdn Refresh job failed on passive device

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Fqdn Refresh job failed on passive device

Cyber Elite
Cyber Elite

we are getting email alert for the Fqdn Refresh job failed on passive device

does passive device need to do the fqdn refresh?

MP

Help the community: Like helpful comments and mark solutions.
2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

I would say yes since if it needs to take over its up to date. Check which interface you are using for the 'Service Path', if it is not the management port, it will not be up on a passive device. Also it could be something else blocking the traffic?

 

Just a few thoughts.

View solution in original post

Cyber Elite
Cyber Elite

@MP18,

As @OtakarKlier mentioned really the default answer to this question would be yes. However, depending on what you're using FQDNs for and how vital they are in your configuration, a laps of an update could potentially be a non/small issue that is acceptable for your organization. A lot of people run into this on passive devices since they aren't using the management port, and in that case I would just say that you shouldn't use any FQDN objects in vital policies. 

That being said, obviously giving the device a dedicated management interface has multiple advantages outside of just allowing FQDN refreshes while passive. If at all possible, I would really recommend that the firewall management port always have a connection and you don't rely on the service routes option. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

I would say yes since if it needs to take over its up to date. Check which interface you are using for the 'Service Path', if it is not the management port, it will not be up on a passive device. Also it could be something else blocking the traffic?

 

Just a few thoughts.

Cyber Elite
Cyber Elite

@MP18,

As @OtakarKlier mentioned really the default answer to this question would be yes. However, depending on what you're using FQDNs for and how vital they are in your configuration, a laps of an update could potentially be a non/small issue that is acceptable for your organization. A lot of people run into this on passive devices since they aren't using the management port, and in that case I would just say that you shouldn't use any FQDN objects in vital policies. 

That being said, obviously giving the device a dedicated management interface has multiple advantages outside of just allowing FQDN refreshes while passive. If at all possible, I would really recommend that the firewall management port always have a connection and you don't rely on the service routes option. 

  • 2 accepted solutions
  • 2136 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!