Hi All ,
I am planning to use FQDN based address for security policy . Any
best practice to follow . As we have concern related to FQDN dns cache on firewall . And if we are connecting to cloud ( using hybrid setup) any specific recommendation for that as well .
Solved! Go to Solution.
There are no as such best practice to follow. The only thing you need to consider is DNS configuration on the firewall. As when FQDN based object is configured on firewall, the MGMT plane sends DNS query requests to the configured DNS servers and populates all the IP addresses associated with configured FQDN object. These IP addresses are then forwarded to dataplane and act according to the security policy actions.
Here for Dataplane, this object only acts as a IP address but not as FQDN/domain. There is limit of max 10 IP addresses which are mapped by firewall to one FQDN object. There's no way to modify this limit. In this type of object, you cant configure wildcard domain. For wildcard domains, custom URL category it the option.
Hope it helps!
Hi Mayur ,
Thanks for your help. My concern was mainly due to FQDN cache on firewalls.
I have one more question.supoose we have fqdn along with Uri path like https://abc.company.com/check/folder..
For this case just using fqdn based address will work or need to go for custom url for this as well.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!