<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Resolution Issue for Spoke Firewalls over MPLS (Using External IP Instead of Internal) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275920#M105077</link>
    <description>&lt;P&gt;i think you are asking sonething that it would trigger&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;local antispoofing&lt;/P&gt;
&lt;P&gt;probably only nat is the solution&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2026 09:24:42 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2026-04-22T09:24:42Z</dc:date>
    <item>
      <title>DNS Resolution Issue for Spoke Firewalls over MPLS (Using External IP Instead of Internal)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275917#M105076</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We have a hub-and-spoke MPLS setup where:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;DNS server is located at the hub site&lt;/LI&gt;&lt;LI&gt;Spoke locations connect via MPLS&lt;/LI&gt;&lt;LI&gt;DNS server is configured to allow queries &lt;STRONG&gt;only from internal network ranges&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":small_blue_diamond:"&gt;🔹&lt;/span&gt; Issue:&lt;/H3&gt;&lt;P&gt;Spoke Check Point firewalls (Gaia&amp;amp; SMBmodels) are unable to resolve DNS for updates (IPS, AV, URL Filtering, etc.).&lt;/P&gt;&lt;P&gt;On investigation:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Firewalls are sending DNS queries using their &lt;STRONG&gt;MPLS WAN (external) IP&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;DNS server blocks these requests since only internal IP ranges are allowed&lt;/LI&gt;&lt;LI&gt;As a result, update services are failing&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":small_blue_diamond:"&gt;🔹&lt;/span&gt; Constraints:&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;At spoke, Only two interfaces are in use (Internal + External)&lt;/LI&gt;&lt;LI&gt;Management interface is not currently used&lt;/LI&gt;&lt;LI&gt;We want to avoid NAT configuration&lt;/LI&gt;&lt;/OL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":small_blue_diamond:"&gt;🔹&lt;/span&gt; Questions:&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Why does the firewall use the external interface IP for DNS queries instead of internal, is there a way to make it initiate using internal interface ip?&lt;/LI&gt;&lt;LI&gt;In Gaia, there is an option:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Network Management → Network Interfaces → Management Interface&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;What exactly does this control?&lt;/LI&gt;&lt;LI&gt;If we assign the internal interface as the management interface, will DNS queries originate from the internal IP?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;This option is not available on SMB:&lt;UL&gt;&lt;LI&gt;Is there an alternative way to control DNS source IP on SMB devices?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;What is the recommended approach in such MPLS deployments?&lt;/LI&gt;&lt;/OL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":small_blue_diamond:"&gt;🔹&lt;/span&gt; Goal:&lt;/H3&gt;&lt;P&gt;Ensure firewall-originated DNS queries use &lt;STRONG&gt;internal IP&lt;/STRONG&gt;, so they are allowed by the DNS server.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;Any guidance or best practices would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 08:32:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275917#M105076</guid>
      <dc:creator>sandeepsutar</dc:creator>
      <dc:date>2026-04-22T08:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution Issue for Spoke Firewalls over MPLS (Using External IP Instead of Internal)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275920#M105077</link>
      <description>&lt;P&gt;i think you are asking sonething that it would trigger&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;local antispoofing&lt;/P&gt;
&lt;P&gt;probably only nat is the solution&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 09:24:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275920#M105077</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2026-04-22T09:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution Issue for Spoke Firewalls over MPLS (Using External IP Instead of Internal)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275921#M105078</link>
      <description>&lt;P&gt;Source address is based on routing, it will take the interface address nearest to the destination.&lt;/P&gt;
&lt;P&gt;MPLS with external IPs would be considered unusual here given IPv4 conservation efforts.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 09:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275921#M105078</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-22T09:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution Issue for Spoke Firewalls over MPLS (Using External IP Instead of Internal)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275945#M105081</link>
      <description>&lt;P&gt;By default, traffic originating from the gateway itself uses the source address of the egress interface per the routing table.&lt;BR /&gt;SMB appliances do have an option to use the internal IP per&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk119415" target="_blank"&gt;&lt;SPAN&gt;sk119415&lt;/SPAN&gt;&lt;/A&gt;.&lt;BR /&gt;Not aware of how to achieve this on non-SMB devices.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 14:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Resolution-Issue-for-Spoke-Firewalls-over-MPLS-Using/m-p/275945#M105081</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-22T14:42:48Z</dc:date>
    </item>
  </channel>
</rss>

