This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

restricted fqdn or ip hosts - problem. Rule does not work

Hi all

I created a firewall allow rule with destination as fqdn (*.microsoft.com). Sadly, the rule does not work and "deny all" rule is applied to traffic. Kindly help



This thread was automatically locked due to age.
Parents
  • You should try Adding the domain in wildcard exceptions in Web-->Exception-->Add Exception

    I have had more success with the above option than creating firewall allow rule with wildcard FQDN hosts.

  • In Firewall rules you can't use wildcard domains. You need a web proxy for wildcard exceptions.

    Regards mod

  • We can create wild card fqdn hosts and map them to a firewall rule.This was newly introduced in v17

  • Can you explain how a wildcard domain is resolved to use this in a paket filter rule? I can't believe that this is possible.

    Regards mod

  • mod2402 said:

    Can you explain how a wildcard domain is resolved to use this in a paket filter rule? I can't believe that this is possible.

    Regards mod

    It is possible, as long as your client uses the XG Firewall for DNS Resolution. In this case, XG Listens on DNS Request for any of your *.yourdomain.com and adds the subdomains it found during DNS-Log-Crawling to the Object. That makes XG possible to resolve FQDN.

     

    But: This is not done in Realtime. It can take a few minutes until a newly created Wildcard DNS takes affect. During my tests it was not working very stable.

  • HuberChristian said:

     

     
    mod2402

    Can you explain how a wildcard domain is resolved to use this in a paket filter rule? I can't believe that this is possible.

    Regards mod

     

     

    It is possible, as long as your client uses the XG Firewall for DNS Resolution. In this case, XG Listens on DNS Request for any of your *.yourdomain.com and adds the subdomains it found during DNS-Log-Crawling to the Object. That makes XG possible to resolve FQDN.

     

    But: This is not done in Realtime. It can take a few minutes until a newly created Wildcard DNS takes affect. During my tests it was not working very stable.

     

     

    It is OK if takes a few minutes. But my problem is it does not even after hours together if I am using the proxy service that is built-in to xg

Reply
  • HuberChristian said:

     

     
    mod2402

    Can you explain how a wildcard domain is resolved to use this in a paket filter rule? I can't believe that this is possible.

    Regards mod

     

     

    It is possible, as long as your client uses the XG Firewall for DNS Resolution. In this case, XG Listens on DNS Request for any of your *.yourdomain.com and adds the subdomains it found during DNS-Log-Crawling to the Object. That makes XG possible to resolve FQDN.

     

    But: This is not done in Realtime. It can take a few minutes until a newly created Wildcard DNS takes affect. During my tests it was not working very stable.

     

     

    It is OK if takes a few minutes. But my problem is it does not even after hours together if I am using the proxy service that is built-in to xg

Children
No Data