How to add firewall rule to a name and not get a performance hit?

view story

http://serverfault.com – I have an internal application sitting behind a firewall that has to FTP some files to uploads.google.com. I asked our network/sys admin to create a rule to allow it and they did, based on the IP of uploads.google.com. However, Google change their IP address for this name from time to time and when they do, obviously the rule stops working. I told them (admins) to use the name instead of the IP Address and they said that the performance hit on the firewall would be too big if it had to resolve names before allowing a package to go out. I'm not an infrastructure guy, but I'm pretty sure th (HowTos)