Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Rule with FQDN

I'm trying to build a business rule for incoming traffic from an fqdn resolved host. As you can see in the image, I have a rule that allows network traffic from two objects. One is an IP address object and the other is an FQDN host that resolves to the exact same IP when I hover over it or issue a DHCP lookup. However, if I set this rule with only the FQDN object in place on the Allowed Client Networks section, traffic is blocked from the host. If I make the rule to include the IP address object in the Allowed Client Network section, it works perfectly (obviously I can leave the FQDN object off completely in this case and it still works).

 

Is there something I'm missing? This type of rule worked perfectly under my UTM 9 setup using an FQDN.



This thread was automatically locked due to age.
Parents
  • Hi Brian,

    I've just tested this on my lab and the Business Application Rule to forward traffic from an FQDN object seems to be working ok, could you share a screenshot of your firewall log for that traffic (turn on logging for the Business Application Rule as well) as well as a screenshot of your FQDN objects when you hover over them and that they are resolving?

    Emile

  • I don't seem to get any logged data from the denied traffic in the log viewer. I added a Drop All user network rule with logging enabled to the bottom of my firewall rule list, but that doesn't seem to add any logging for this particular issue. The TCP dump data is above and here is the screen shot of the FQDN resolving below.

     

Reply
  • I don't seem to get any logged data from the denied traffic in the log viewer. I added a Drop All user network rule with logging enabled to the bottom of my firewall rule list, but that doesn't seem to add any logging for this particular issue. The TCP dump data is above and here is the screen shot of the FQDN resolving below.

     

Children
No Data