The point is that it was working fine while testing.
Firewall blade saw two FQDNs perfectly. I've created two domain objects pointed to the same GW-Extrernal address.
I found Logs especially for you)
Two separate external sources - .199 and .66. Look on the Access Rule number. One source goes through rule 5 and another through rule 4.
And here are logs which shows that fqdns is matching perfectly. Firewall blade sees every FQDN:
Now you see that Firewall Blade saw every FQDN (test123 and asdasd) perfectly even if they were pointed to the same IP .30.
That is my problem. Firewall Blade forgot how to do it)
By your logic, logs must show only one fqdn, and acces only via one rule. That is happening now. But back then... So i think we have to remind Firewall how to do it.