NGFW policy support for FQDN address groups in the ISDB 7.6.5
|
|
This information is also available in the FortiOS 7.6 Administration Guide: |
Fully Qualified Domain Name (FQDN) address groups within the Internet Service Database (ISDB) can be applied to NGFW policies. Previously only firewall policies were supported.
|
|
This is an extension of a FortiOS new feature introduced in 7.6.1 and updated in 7.6.4. For more information, see Apply FQDN address groups within the ISDB 7.6.1 and GUI support for FQDN address groups within the ISDB 7.6.4. |
Example
In the following example, an FQDN internet service is applied as internet-service-fortiguard to a security policy. When a client sends packets to the destination that matches this FQDN Internet Service, the security policy is triggered, and the traffic is processed according to the security policy rules.
To apply an FQDN from the ISDB to a security policy in the CLI:
-
Ensure policy-based NGFW mode is enabled. See NGFW policy for more information.
-
Apply the built-in FQDN entry to a security policy in NGFW policy-based mode:
config firewall security-policy edit 100 set uuid 4473436c-9b01-51f0-eea3-44af202bf3a1 set srcintf "port3" set dstintf "port1" set srcaddr "all" set internet-service enable set internet-service-fortiguard "FQDN-Microsoft-Microsoft.Update" set action accept set schedule "always" set logtraffic all next end -
Send packets from the client to the FQDN domain
windowsupdate.microsoft.com(IP address128.85.102.70), which is one of the FQDN domains included inFQDN-Microsoft-Microsoft.Update. The traffic is affected, and FortiGate forwards the traffic according to the security policy.1: date=2025-09-26 time=10:54:25 eventtime=1758909265590012214 tz="-0700" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="vdom1" srcip=10.1.100.11 identifier=987 srcintf="port3" srcintfrole="undefined" dstip=128.85.102.70 dstintf="port1" dstintfrole="undefined" srccountry="Reserved" dstinetsvc="FQDN-Microsoft-Microsoft.Update" dstcountry="United States" dstregion="Washington" dstcity="Quincy" sessionid=10391 proto=1 action="accept" policyid=100 policytype="security-policy" poluuid="4473436c-9b01-51f0-eea3-44af202bf3a1" centralnatid=1 service="FQDN-Microsoft-Microsoft.Update" trandisp="snat" transip=172.16.200.68 appid=24466 app="Ping" appcat="Network.Service" apprisk="elevated" duration=119 sentbyte=4956 rcvdbyte=0 sentpkt=59 rcvdpkt=0 srchwvendor="Fortinet" devtype="Router" srcfamily="FortiGate" osname="FortiOS" srchwversion="200F" mastersrcmac="d4:76:a0:03:23:38" srcmac="d4:76:a0:03:23:38" srcserver=0 dstdevtype="Unknown" dstosname="Unknown" masterdstmac="90:6c:ac:c2:75:cb" dstmac="90:6c:ac:c2:75:cb" dstserver=0