Hi Experts,
We are using R81.20 take 26 as our firewall, and have some NAT rules. All the traffic is routed to Datacenter through a GRE tunnel.
But we still have some traffic needs to bypass the tunnel and NAT to internet directly. In the NAT rules, we use Host Group as destination and all hosts are IP address.
My question is, is it possible to put the Domain Groups ( Domain objects ) into the destination? including FQDN and non-FQDN. As the URL/domains are based on AWS CDN service and the IPs varies.
If it doesn't support, should I use DNS Checker to find out all the IP addresses' public resolution for the domains, and add all the IPs to the destination? That would be a manual work and needs to update frequently if the server's IP changed.
Thanks very much
Best regards
George