Fortinet black logo

New Features

Resolve IP address from FQDN for firewall address type subnet

Copy Link
Copy Doc ID 722c6141-8e83-11ec-9fd1-fa163e15d75b:102359
Download PDF

Resolve IP address from FQDN for firewall address type subnet

In FortiManager, you can resolve the IP address from the FQDN for "subnet" type firewall addresses.

To resolve IP/Netmask from the FQDN in IPv4 address objects:
  1. Go to Policy & Objects > Object Configurations > Firewall Objects > Addresses.
  2. Create or edit a firewall address object.
  3. In the Address Name field, enter the FQDN. For example, www.google.com.
  4. In the Type field, leave the address as Subnet.
  5. In the IP/Netmask field, click Resolve from name.
    The field is auto-filled with the first IP retrieved from the DNS query.
  6. The saved address can be used in a policy.
  7. If FortiManager cannot resolve the host name/FQDN, the GUI will report the following error: Name or service not known.
To resolve IP/Netmask from the FQDN in IPv6 address objects:
  1. Go to Policy & Objects > Object Configurations > Firewall Objects > Addresses.
  2. Create or edit a firewall address object.
  3. In the Address Name field, enter the FQDN. For example, www.google.com.
  4. In the Type field, leave the address as IPv6 Subnet.
  5. In the IP/Netmask field, click Resolve from name.
    The field is auto-filled with the first IP retrieved from the DNS query.
  6. The saved address can be used in a policy.

Resolve IP address from FQDN for firewall address type subnet

In FortiManager, you can resolve the IP address from the FQDN for "subnet" type firewall addresses.

To resolve IP/Netmask from the FQDN in IPv4 address objects:
  1. Go to Policy & Objects > Object Configurations > Firewall Objects > Addresses.
  2. Create or edit a firewall address object.
  3. In the Address Name field, enter the FQDN. For example, www.google.com.
  4. In the Type field, leave the address as Subnet.
  5. In the IP/Netmask field, click Resolve from name.
    The field is auto-filled with the first IP retrieved from the DNS query.
  6. The saved address can be used in a policy.
  7. If FortiManager cannot resolve the host name/FQDN, the GUI will report the following error: Name or service not known.
To resolve IP/Netmask from the FQDN in IPv6 address objects:
  1. Go to Policy & Objects > Object Configurations > Firewall Objects > Addresses.
  2. Create or edit a firewall address object.
  3. In the Address Name field, enter the FQDN. For example, www.google.com.
  4. In the Type field, leave the address as IPv6 Subnet.
  5. In the IP/Netmask field, click Resolve from name.
    The field is auto-filled with the first IP retrieved from the DNS query.
  6. The saved address can be used in a policy.