Wednesday, October 28, 2020

FQDNs That Resolve To Multiple IPs and Firewall Rules

I have a problem that I haven't been able to find answers to with my Google-fu. Our internal workstations need to connect to an antivirus service in the cloud. The hostname they use is whatever.antivirus.com, which resolves to multiple IP addresses. The workstations use the domain controllers for DNS.

The problem is that sometimes the workstations resolve whatever.antivirus.com and get 1.2.3.4 for the IP but then can't connect to it. It seems what's happening is the firewall is querying whatever.antivirus.com and getting a different IP address such as 5.6.7.8, and therefore blocks the workstation's request to 1.2.3.4.

I'm sure a solution must exist for this but I don't know the terms to search for.

Thanks in advance!



No comments:

Post a Comment