05-22-2025 08:32 AM
Good Morning Team,
I'm trying to allow HTTPS traffic sourced from an Internal server in our DMZ , to FQDNS using a rule applied to our current ACP running on our FTDs. Here is the following rule:
Source
Zone (object DMZ)
NET (Object (Server IP)
Port (Type: Port / Value TCP: 443)
Destination
ZONE (Corp - Outside)
Port (TCP:443)
URL (Listed FQDNs)
Should I have a network listed in the destination as well?
Thanks in Advance,
James
Solved! Go to Solution.
05-22-2025 09:05 AM
URL rules with FQDNs do not require a network address. Note however that for them to work consistently, the DNS server used by the firewall should match that being used by the clients. We can sometimes see differing lookup results when they don't match. Even when they do, varying DNS cache timeouts and use of CDNs by the hosting provider can sometimes cause issues.
05-22-2025 09:05 AM
URL rules with FQDNs do not require a network address. Note however that for them to work consistently, the DNS server used by the firewall should match that being used by the clients. We can sometimes see differing lookup results when they don't match. Even when they do, varying DNS cache timeouts and use of CDNs by the hosting provider can sometimes cause issues.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide