Monday, October 2, 2017

FortiOS FQDN address objects blues

Playing around with long DNS name and  FQDN objects I found  a issue.

1> when trying to delete a FQDN object under 5.2.11, the appliance would NOT allow me to delete it


2>  the cache-tty value in the address book was set to a low number;


3> The NS hosting this   FQDN was change and the update was pushed but the fortigate cache-ttl did not refresh immediately.



So the  address.object should have picked up the 1.1.1.12 address.



Ken



 
NSE ( network security expert) and Route/Switching Engineer
kfelix  -----a----t---- socpuppets ---dot---com
     ^      ^
=(  @  @ )=
         o 


        /  \




No comments:

Post a Comment