Description

[SD-Cloud] SRX adoption might fail due to FQDN firewall policy

Solution

For example:

 

  • SRX-A needs to connect to SD-Cloud, and the traffic must cross SRX-B; hence, an FQDN firewall policy is configured in SRX-B. 
  • In this scenario, we need to ensure that the DNS server resolves the same IP address in both firewalls so that the traffic will be allowed by the FQDN firewall policy.
  • If SRX-A and SRX-B resolve different IPs, then the traffic will be blocked.

Modification History

2024-05-26 : Article Created