<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block IP but not FQDN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136442#M20607</link>
    <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;Can we block the network traffic to the IP, but allow if the traffic is pointing to a FQDN?&lt;/P&gt;&lt;P&gt;The idea here is to block the scanners looking for public IPs for open ports.&lt;/P&gt;&lt;P&gt;If so, ho can we achieve that ? The software version used here is R80.40&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;</description>
    <pubDate>Wed, 15 Dec 2021 16:21:36 GMT</pubDate>
    <dc:creator>h2k</dc:creator>
    <dc:date>2021-12-15T16:21:36Z</dc:date>
    <item>
      <title>Block IP but not FQDN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136442#M20607</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;Can we block the network traffic to the IP, but allow if the traffic is pointing to a FQDN?&lt;/P&gt;&lt;P&gt;The idea here is to block the scanners looking for public IPs for open ports.&lt;/P&gt;&lt;P&gt;If so, ho can we achieve that ? The software version used here is R80.40&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 16:21:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136442#M20607</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2021-12-15T16:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP but not FQDN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136450#M20611</link>
      <description>&lt;P&gt;There's not a way to do that, no. Connections are always to an IP address. The firewall can't tell if somebody else got the IP address by picking a number or by looking up a name.&lt;/P&gt;
&lt;P&gt;You could set up canary ports or addresses. For example, if a client out on the Internet tries to connect to port 80 when you only offer HTTPS, block them for some period of time. Or reserve an IP at the end of your address range and declare it will never be used, and never put in DNS. Then if a client tries to connect, you know it's a scan and you can block them. They will get results until they hit the canary, but that's probably not avoidable.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 17:06:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136450#M20611</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-12-15T17:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP but not FQDN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136465#M20621</link>
      <description>&lt;P&gt;You can use SmartEvent to block those scanners. There is a protection available to block scanners for time x if detected.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 19:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136465#M20621</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-12-15T19:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP but not FQDN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136469#M20623</link>
      <description>&lt;P&gt;Thanks! What are the best practices to implement SmartEvent within Checkpoint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 20:14:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136469#M20623</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2021-12-15T20:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP but not FQDN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136470#M20624</link>
      <description>&lt;P&gt;Thanks! Do we have any other best practices to detect and block the suspicious traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 20:15:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-IP-but-not-FQDN/m-p/136470#M20624</guid>
      <dc:creator>h2k</dc:creator>
      <dc:date>2021-12-15T20:15:51Z</dc:date>
    </item>
  </channel>
</rss>

