<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High number of DNS queries generated by Cloudguard firewalls for microsoft domains in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47967#M2997</link>
    <description>&lt;P&gt;It's contastly checking with azure api backend, that's why so many dns hits..&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 13:30:25 GMT</pubDate>
    <dc:creator>Martin_Valenta</dc:creator>
    <dc:date>2019-03-20T13:30:25Z</dc:date>
    <item>
      <title>High number of DNS queries generated by Cloudguard firewalls for microsoft domains</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47943#M2996</link>
      <description>&lt;P&gt;We are seeing high number of DNS requests made by our R80.10 (JHF Take 169) Cloudguard firewalls running FW/URLF/APPI blades to management.azure.com and blob.core.windows.net every second to our DNS server on 10.64.17.10&lt;/P&gt;&lt;P&gt;We do not have a domain object defined for these domains&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;12:24:56.972268 IP 172.26.163.36.62901 &amp;gt; 10.64.17.10.domain: 5418+ AAAA? md-r425qqtbx25f.blob.core.windows.net. (55)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:56.985671 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.62901: 5418 1/1/0 CNAME blob.am4prdstr02a.store.core.windows.net. (179)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:56.985900 IP 172.26.163.36.54997 &amp;gt; 10.64.17.10.domain: 28673+ A? md-r425qqtbx25f.blob.core.windows.net. (55)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:56.998820 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.54997: 28673 2/0/0 CNAME blob.am4prdstr02a.store.core.windows.net., A 40.118.73.208 (109)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.024426 IP 172.26.163.36.49448 &amp;gt; 10.64.17.10.domain: 19122+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.038050 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.49448: 19122 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.325273 IP 172.26.163.36.45648 &amp;gt; 10.64.17.10.domain: 38158+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.338527 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.45648: 38158 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.576465 IP 172.26.163.36.33918 &amp;gt; 10.64.17.10.domain: 37507+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.595217 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.33918: 37507 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.830215 IP 172.26.163.36.52092 &amp;gt; 10.64.17.10.domain: 14287+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:57.843584 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.52092: 14287 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:58.130100 IP 172.26.163.36.46677 &amp;gt; 10.64.17.10.domain: 35906+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:58.142549 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.46677: 35906 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:58.381202 IP 172.26.163.36.56930 &amp;gt; 10.64.17.10.domain: 4052+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:58.394089 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.56930: 4052 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:59.722341 IP 172.26.163.36.56899 &amp;gt; 10.64.17.10.domain: 41422+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:24:59.735676 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.56899: 41422 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:25:00.057386 IP 172.26.163.36.61066 &amp;gt; 10.64.17.10.domain: 21154+ A? management.azure.com. (38)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;12:25:00.072370 IP 10.64.17.10.domain &amp;gt; 172.26.163.36.61066: 21154 4/0/0 CNAME arm-rpfd-prod.trafficmanager.net., CNAME uksouth.management.azure.com., CNAME rpfd-prod-ln-01.cloudapp.net., A 51.140.3.40 (161)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I have spoken to R&amp;amp;D through our SE and they say that this is by design which I really don't get. Anyone else seen this behaviour with Cloudguard firewalls ?&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 12:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47943#M2996</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2019-03-20T12:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: High number of DNS queries generated by Cloudguard firewalls for microsoft domains</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47967#M2997</link>
      <description>&lt;P&gt;It's contastly checking with azure api backend, that's why so many dns hits..&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 13:30:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47967#M2997</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2019-03-20T13:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: High number of DNS queries generated by Cloudguard firewalls for microsoft domains</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47976#M2998</link>
      <description>&lt;P&gt;What I dont get is that why does the FW send 6-7 requests for same domain each second when the TTL on these records is set to 10 secs (for the A record)&lt;/P&gt;&lt;P&gt;[Expert@fw1:0]# dig management.azure.com&lt;/P&gt;&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.3.6-P1-RedHat-9.3.6-25.P1.11.cp991310011 &amp;lt;&amp;lt;&amp;gt;&amp;gt; management.azure.com&lt;BR /&gt;;; global options: printcmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 2104&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 0&lt;/P&gt;&lt;P&gt;;; QUESTION SECTION:&lt;BR /&gt;;management.azure.com. IN A&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;BR /&gt;management.azure.com. 373 IN CNAME arm-rpfd-prod.trafficmanager.net.&lt;BR /&gt;arm-rpfd-prod.trafficmanager.net. 13 IN CNAME uknorth.management.azure.com.&lt;BR /&gt;uknorth.management.azure.com. 1634 IN CNAME rpfd-prod-mm-01.cloudapp.net.&lt;BR /&gt;rpfd-prod-mm-01.cloudapp.net. 4 IN A 13.87.77.81&lt;/P&gt;&lt;P&gt;;; Query time: 12 msec&lt;BR /&gt;;; SERVER: 10.64.17.10#53(10.64.17.10)&lt;BR /&gt;;; WHEN: Wed Mar 20 14:16:22 2019&lt;BR /&gt;;; MSG SIZE rcvd: 161&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-number-of-DNS-queries-generated-by-Cloudguard-firewalls-for/m-p/47976#M2998</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2019-03-20T14:18:36Z</dc:date>
    </item>
  </channel>
</rss>

