- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-18-2020 03:00 AM
Hi All ,
I am planning to use FQDN based address for security policy . Any
best practice to follow . As we have concern related to FQDN dns cache on firewall . And if we are connecting to cloud ( using hybrid setup) any specific recommendation for that as well .
Thanks
07-22-2020 11:34 PM - edited 07-22-2020 11:36 PM
@deepak12It will work.
For data plane request for https://abc.company.com/check/folder.. will get as https://<FQDN-IP-Address>/check/folder..
You only need to add object without https:// and any URI.
Mayur
07-22-2020 07:43 AM - edited 07-22-2020 07:45 AM
There are no as such best practice to follow. The only thing you need to consider is DNS configuration on the firewall. As when FQDN based object is configured on firewall, the MGMT plane sends DNS query requests to the configured DNS servers and populates all the IP addresses associated with configured FQDN object. These IP addresses are then forwarded to dataplane and act according to the security policy actions.
Here for Dataplane, this object only acts as a IP address but not as FQDN/domain. There is limit of max 10 IP addresses which are mapped by firewall to one FQDN object. There's no way to modify this limit. In this type of object, you cant configure wildcard domain. For wildcard domains, custom URL category it the option.
Hope it helps!
Mayur
07-22-2020 07:52 AM
Hi Mayur ,
Thanks for your help. My concern was mainly due to FQDN cache on firewalls.
I have one more question.supoose we have fqdn along with Uri path like https://abc.company.com/check/folder..
For this case just using fqdn based address will work or need to go for custom url for this as well.
Thanks..
07-22-2020 11:34 PM - edited 07-22-2020 11:36 PM
@deepak12It will work.
For data plane request for https://abc.company.com/check/folder.. will get as https://<FQDN-IP-Address>/check/folder..
You only need to add object without https:// and any URI.
Mayur
12-07-2023 12:35 PM
Hello All,
Also use a secure DNS provider as an added layer. https://www.youtube.com/watch?v=ROIAYSEbTuo
Regards,
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!