<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW access to domain &amp;quot;accountsupportteam.com&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110460#M15170</link>
    <description>&lt;P&gt;What kind of gateway running what version of code?&lt;BR /&gt;My guess is that one of the clients is doing it.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Feb 2021 15:22:16 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-02-10T15:22:16Z</dc:date>
    <item>
      <title>FW access to domain "accountsupportteam.com"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110455#M15169</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our CP Firewalls are constantly trying to reach out a domain named "accountsupportteam.com"&lt;/P&gt;&lt;P&gt;according to some sources in VirusTotal this domain is recognized as a malicious domain.&lt;/P&gt;&lt;P&gt;Does it familiar to someone? Why are they reach out to this domain?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 14:42:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110455#M15169</guid>
      <dc:creator>Dvirg</dc:creator>
      <dc:date>2021-02-10T14:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: FW access to domain "accountsupportteam.com"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110460#M15170</link>
      <description>&lt;P&gt;What kind of gateway running what version of code?&lt;BR /&gt;My guess is that one of the clients is doing it.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 15:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110460#M15170</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-10T15:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: FW access to domain "accountsupportteam.com"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110461#M15171</link>
      <description>&lt;P&gt;Reach out how? Are you able to share a redacted log card for the communication...&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 15:24:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110461#M15171</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-02-10T15:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: FW access to domain "accountsupportteam.com"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110751#M15231</link>
      <description>&lt;P&gt;After an investigation and help from CP-Support, I found this object in "Object Explorer", and it turned out that the GWs are validating FQDN requests.&lt;BR /&gt;Thank you all for your help.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Feb 2021 08:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-access-to-domain-quot-accountsupportteam-com-quot/m-p/110751#M15231</guid>
      <dc:creator>Dvirg</dc:creator>
      <dc:date>2021-02-14T08:36:32Z</dc:date>
    </item>
  </channel>
</rss>

