<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain Objects on R80.10 allow three similar FQDNs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/109197#M14805</link>
    <description>&lt;P&gt;Just tested with&amp;nbsp;.d2m0sklryvkyy2.cloudfront.net and it is not blocked.&amp;nbsp;&lt;BR /&gt;I have tested with just a regular hostname webmail.domain.com that resolves to an unique ip and it is blocked.&lt;BR /&gt;So I guess that it may struggle with&amp;nbsp;d2m0sklryvkyy2.cloudfront.net because it resolves to more than one ip.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 15:54:21 GMT</pubDate>
    <dc:creator>Luis_Miguel_Mig</dc:creator>
    <dc:date>2021-01-28T15:54:21Z</dc:date>
    <item>
      <title>Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/57345#M4306</link>
      <description>&lt;P&gt;I want to allow three sites hosted by a well known cloud provider to be defined via Domain Objects in FQDN mode.&lt;/P&gt;&lt;P&gt;The sites are:&lt;/P&gt;&lt;P&gt;blog.cloudserviceco.com&lt;/P&gt;&lt;P&gt;aaa.cloudserviceco.com&lt;/P&gt;&lt;P&gt;tcl.cloudserviceco.com&lt;/P&gt;&lt;P&gt;Do I set these up as is or with a period (.) before each one. I do not want to use just .cloudserviceco.com unless this is the only way forward.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 13:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/57345#M4306</guid>
      <dc:creator>star-domain</dc:creator>
      <dc:date>2019-07-03T13:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/57406#M4309</link>
      <description>Set them up as is with a period in front.</description>
      <pubDate>Thu, 04 Jul 2019 01:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/57406#M4309</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-04T01:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/68611#M5265</link>
      <description>&lt;P&gt;HI All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with regard to FQDN objects in a policy I want to use for example 3 hosts&lt;/P&gt;&lt;P&gt;a.cloudservice.com&lt;/P&gt;&lt;P&gt;b.cloudservice.com&lt;/P&gt;&lt;P&gt;c.cloudservice.com&lt;/P&gt;&lt;P&gt;Do I just add 3 domain objects as follows .a.cloudservice.com, b. cloudservice.com and .c.cloudservice.com with the period in front? if you do a nslookup of this it doesn't work so does Checkpoint treat this differently to remove the . ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 09:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/68611#M5265</guid>
      <dc:creator>Alan_Camelo1</dc:creator>
      <dc:date>2019-11-27T09:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/68702#M5266</link>
      <description>Yes we remove the leading dot in the object name.</description>
      <pubDate>Wed, 27 Nov 2019 17:13:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/68702#M5266</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-27T17:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108520#M14638</link>
      <description>&lt;P&gt;running r80.40, if I configure&amp;nbsp; a&amp;nbsp; host for example .mail.google.com and add it to a policy I get&amp;nbsp; the following error ".mail.google.com' can't be resolved to an ip address.&lt;BR /&gt;My firewall manager has dns configured and resolves names&lt;BR /&gt;I get the same error even with .google.com&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108520#M14638</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2021-01-22T14:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108567#M14649</link>
      <description>&lt;P&gt;Can the gateway resolve DNS names?&lt;BR /&gt;This is required on every gateway that is enforcing this policy.&lt;/P&gt;
&lt;P&gt;Where precisely are you getting this error message?&lt;BR /&gt;Can you provide a screenshot?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 18:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108567#M14649</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-22T18:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108742#M14716</link>
      <description>&lt;P&gt;Yes it resolves dns names. I wonder if it is only a cosmetic issue before I install the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 10:05:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108742#M14716</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2021-01-25T10:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108775#M14726</link>
      <description>&lt;P&gt;I have eventually installed the policy with that warning and it works for a FQDN entry for .checkpoint.com but it doesn't for .community.checkpoint.com. It doesn't match it which I think it is consistent with my understanding of the user guides. So I am a bit confused, you guys seem to expect that it should work for hostnames too&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 16:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108775#M14726</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2021-01-25T16:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108782#M14728</link>
      <description>&lt;P&gt;FQDN == Fully Qualified Domain Name.&lt;BR /&gt;I suspect the issue is that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;checkpoint.com resolves directly to an A record (i.e. an IP address)&lt;/LI&gt;
&lt;LI&gt;community.checkpoint.com resolves to a CNAME (i.e. an alias that, in this case, points to another alias, which points to multiple IP addresses)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I assume if you put the hostname that community.checkpoint.com ultimately resolves to, which is d2m0sklryvkyy2.cloudfront.net, that will work.&lt;BR /&gt;I did find one TAC case that suggests this should have been fixed at some point.&lt;BR /&gt;Please engage with the TAC, but meanwhile you can employ the above workaround (use the host the CNAME record ultimately resolves to).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 16:42:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/108782#M14728</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-25T16:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/109197#M14805</link>
      <description>&lt;P&gt;Just tested with&amp;nbsp;.d2m0sklryvkyy2.cloudfront.net and it is not blocked.&amp;nbsp;&lt;BR /&gt;I have tested with just a regular hostname webmail.domain.com that resolves to an unique ip and it is blocked.&lt;BR /&gt;So I guess that it may struggle with&amp;nbsp;d2m0sklryvkyy2.cloudfront.net because it resolves to more than one ip.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 15:54:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/109197#M14805</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2021-01-28T15:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/109201#M14806</link>
      <description>&lt;P&gt;It should work in the other case as well, which suggests a bug.&lt;BR /&gt;A TAC case is definitely in order.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:28:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/109201#M14806</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-28T16:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/110906#M15261</link>
      <description>&lt;P&gt;I have upgraded to take 91 and it resolves the alias issue.&lt;BR /&gt;However I am facing a challenge that it may require a different approach.&lt;BR /&gt;I am tasting with "mail.google.com" that seems to present resolve different ips depending on your geolocation.&lt;BR /&gt;So I have different dns servers in the checkpoint servers and my test host that makes the http request. They both get different ips for mail.google.com.&lt;BR /&gt;&lt;BR /&gt;Can checkpoint do anything with that?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 10:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/110906#M15261</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2021-02-16T10:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Objects on R80.10 allow three similar FQDNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/110936#M15272</link>
      <description>&lt;P&gt;Not much you can do in this case except to align the DNS servers used by the client and gateways.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 16:52:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Objects-on-R80-10-allow-three-similar-FQDNs/m-p/110936#M15272</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-16T16:52:42Z</dc:date>
    </item>
  </channel>
</rss>

