<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Domain Object CNAME Question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138008#M20924</link>
    <description>&lt;P&gt;I have a query regarding how Domain objects handle CNAMES following trying to configure specific access for a customer system, which doesn't work when I specify the domains they've told me to allow.&lt;/P&gt;&lt;P&gt;I’ve done some testing in my lab.&amp;nbsp;&amp;nbsp;Please also refer to the screenshot lower down.&lt;/P&gt;&lt;P&gt;A DNS lookup on &lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com&lt;/FONT&gt; returns &lt;FONT color="#0000FF"&gt;s3-1-w.amazonaws.com&lt;/FONT&gt;, which in turn returns &lt;FONT color="#0000FF"&gt;s3-w.us-east-1.amazonaws.com&lt;/FONT&gt;, which in turn gives an IP address to connect to.&amp;nbsp; The IP address is different every time you refresh.&lt;/P&gt;&lt;P&gt;In my lab I allowed the name &lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com&lt;/FONT&gt;.&amp;nbsp; The page timed out and other traffic was also dropped.&lt;/P&gt;&lt;P&gt;In my lab I then allowed all three names:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#0000FF"&gt;s3-1-w.amazonaws.com&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#0000FF"&gt;s3-w.us-east-1.amazonaws.com&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The page still timed out.&lt;/P&gt;&lt;P&gt;In my lab I then allowed &lt;FONT color="#0000FF"&gt;*.amazonaws.com&lt;/FONT&gt;&amp;nbsp; (i.e &lt;FONT color="#0000FF"&gt;.amazonaws.com&lt;/FONT&gt; with the FQDN box unticked).&amp;nbsp; The page now loads immediately.&lt;/P&gt;&lt;P&gt;I’m not yet sure why it didn’t work when I allowed all of the names shown in the tcpdump.&amp;nbsp; But it seems quite clear that allowing a specific domain name in the rule doesn't automatically allow any CNAME's it resolves to.&amp;nbsp; I don't want to allow the whole of amazonaws.com.&lt;/P&gt;&lt;P&gt;Does anyone have any thoughts?&amp;nbsp; Am I doing something wrong?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zadara.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14825i4F4430344D1ACC92/image-size/large?v=v2&amp;amp;px=999" role="button" title="zadara.png" alt="zadara.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jan 2022 08:34:07 GMT</pubDate>
    <dc:creator>biskit</dc:creator>
    <dc:date>2022-01-10T08:34:07Z</dc:date>
    <item>
      <title>Domain Object CNAME Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138008#M20924</link>
      <description>&lt;P&gt;I have a query regarding how Domain objects handle CNAMES following trying to configure specific access for a customer system, which doesn't work when I specify the domains they've told me to allow.&lt;/P&gt;&lt;P&gt;I’ve done some testing in my lab.&amp;nbsp;&amp;nbsp;Please also refer to the screenshot lower down.&lt;/P&gt;&lt;P&gt;A DNS lookup on &lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com&lt;/FONT&gt; returns &lt;FONT color="#0000FF"&gt;s3-1-w.amazonaws.com&lt;/FONT&gt;, which in turn returns &lt;FONT color="#0000FF"&gt;s3-w.us-east-1.amazonaws.com&lt;/FONT&gt;, which in turn gives an IP address to connect to.&amp;nbsp; The IP address is different every time you refresh.&lt;/P&gt;&lt;P&gt;In my lab I allowed the name &lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com&lt;/FONT&gt;.&amp;nbsp; The page timed out and other traffic was also dropped.&lt;/P&gt;&lt;P&gt;In my lab I then allowed all three names:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#0000FF"&gt;s3-1-w.amazonaws.com&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#0000FF"&gt;s3-w.us-east-1.amazonaws.com&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The page still timed out.&lt;/P&gt;&lt;P&gt;In my lab I then allowed &lt;FONT color="#0000FF"&gt;*.amazonaws.com&lt;/FONT&gt;&amp;nbsp; (i.e &lt;FONT color="#0000FF"&gt;.amazonaws.com&lt;/FONT&gt; with the FQDN box unticked).&amp;nbsp; The page now loads immediately.&lt;/P&gt;&lt;P&gt;I’m not yet sure why it didn’t work when I allowed all of the names shown in the tcpdump.&amp;nbsp; But it seems quite clear that allowing a specific domain name in the rule doesn't automatically allow any CNAME's it resolves to.&amp;nbsp; I don't want to allow the whole of amazonaws.com.&lt;/P&gt;&lt;P&gt;Does anyone have any thoughts?&amp;nbsp; Am I doing something wrong?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zadara.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14825i4F4430344D1ACC92/image-size/large?v=v2&amp;amp;px=999" role="button" title="zadara.png" alt="zadara.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 08:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138008#M20924</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-01-10T08:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object CNAME Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138025#M20926</link>
      <description>&lt;P&gt;I don't know exactly how CNAME is handled but you can check each domain object following this sk:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk161632" target="_blank"&gt;Domains Tool (domains_tool) (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It probably works correctly but as a domain object is a simple DNS lookup (from what I know) it's not that reliable if the IPs change very often which seems to be the case in your scenario. So first check what the gateways think about the domain name with the domain tool from the sk.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 11:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138025#M20926</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2022-01-10T11:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object CNAME Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138257#M20979</link>
      <description>&lt;P&gt;When using FQDN objects (domain object with FQDN checkbox ticked), all gateways using this object in their policy are periodically (once per minute) do DNS forward lookups for this FQDN and cache the results in a table. This cache table is used for rulebase lookups with new connections.&lt;/P&gt;
&lt;P&gt;This means that you have to give your gateway some time to cache all possible ip addresses for this FQDN in its cache table before doing your tests. Otherwise it could happen that your test client uses an IP address, not already known to the gateway. You can observe this growing table with the command provided by Marcel.&lt;/P&gt;
&lt;P&gt;This only works that way, when your version is not to old. R80.10 JHF T142, better R80.20 and above.&lt;/P&gt;
&lt;P&gt;Edit: It does not matter how long the CNAME (or DNAME) chain is. You can use ".&lt;FONT color="#0000FF"&gt;zadarastorage-install.s3.amazonaws.com"&lt;/FONT&gt; as FQDN object without problems. Please make sure not to forget the leading dot (even if it makes no sense on the first sight).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 12:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138257#M20979</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-01-12T12:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object CNAME Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138297#M20981</link>
      <description>&lt;P&gt;It's also important that clients use the same DNS path as the firewall. This is mostly a concern for older topologies where clients in an office go over a WAN connection into a datacenter somewhere else to be filtered by a firewall in the datacenter. I've seen some environments where there were multiple such central datacenters around the country, all client DNS went out one by default, but actual client traffic could go out any of them. That caused problems because the site they were trying to reach used DNS-based load distribution, so the firewalls didn't all learn the same IPs for it.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 15:33:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138297#M20981</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-01-12T15:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object CNAME Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138308#M20983</link>
      <description>&lt;P&gt;I asked this question a while back and the answer I got at that point was that the gateways resolve the FQDN during policy installation and caches the result with the TTL from the DNS-response.&lt;/P&gt;&lt;P&gt;I haven't verified this but it makes sense to follow the TTL configured for the DNS-name to avoid unnecessary DNS-queries.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 17:41:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object-CNAME-Question/m-p/138308#M20983</guid>
      <dc:creator>Mikael</dc:creator>
      <dc:date>2022-01-12T17:41:04Z</dc:date>
    </item>
  </channel>
</rss>

