- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
No you cannot use * for both options. So if you enable FQDN or disable it you have to work with a dot (.) not with *
Select FQDN
In the object name, use the Fully Qualified Domain Name (FQDN). Use the format . x.y.z (with a dot "." before the FQDN). For example, if you use . www.example.com then the Gateway matches www.example.com
This option is supported for R80.10 and higher, and is the default. It is more accurate and faster than the non-FQDN option.
The Security Gateway looks up the FQDN with a direct DNS query, and uses the result in the Rule Base
This option supports SecureXL
Accept templates. Using domain objects with this option in a rule has no effect on the performance of the rule, or of the rules that come after it.
Clear FQDN
This option enforces the domain and its sub-domains. In the object name, use the format . x.y for the name. For example, use . example.com or . example.co.uk for the name. If you use . example.com, then the Gateway matches www.example.com and support.example.com
The Gateway does the name resolution using DNS reverse lookups, which can be inaccurate. The Gateway uses the result in the Rule Base, and caches the result to use again.
Also, for the context, that option for fqdn also matters, depending on exactly what you are accessing @Cvr
Andy
No you cannot use * for both options. So if you enable FQDN or disable it you have to work with a dot (.) not with *
Select FQDN
In the object name, use the Fully Qualified Domain Name (FQDN). Use the format . x.y.z (with a dot "." before the FQDN). For example, if you use . www.example.com then the Gateway matches www.example.com
This option is supported for R80.10 and higher, and is the default. It is more accurate and faster than the non-FQDN option.
The Security Gateway looks up the FQDN with a direct DNS query, and uses the result in the Rule Base
This option supports SecureXL
Accept templates. Using domain objects with this option in a rule has no effect on the performance of the rule, or of the rules that come after it.
Clear FQDN
This option enforces the domain and its sub-domains. In the object name, use the format . x.y for the name. For example, use . example.com or . example.co.uk for the name. If you use . example.com, then the Gateway matches www.example.com and support.example.com
The Gateway does the name resolution using DNS reverse lookups, which can be inaccurate. The Gateway uses the result in the Rule Base, and caches the result to use again.
I have not tested that in some time, but it has to start with a . sign.
Andy
Also, for the context, that option for fqdn also matters, depending on exactly what you are accessing @Cvr
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 8 | |
| 7 | |
| 7 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY