Thursday, August 29, 2019

Zonefirewall only with DNS Objects

Hi all,

Im wondering if there are any disadvantages or recommendations against using only FQDN Firewall Objects on Common Firewalls like Fortigate/PaloAlto instead of static IP Address Objects. Especially also for LAN objects like internal firewall zone objects (servers etc.)

The advantages are clear. Much less effort, more dynamic handling etc.

But im wondering if there are some good reasons or maybe best practices against it?



No comments:

Post a Comment