<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain based objects - what is the solution in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145766#M23039</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27524"&gt;@carl_t&lt;/a&gt;&amp;nbsp;Domain Objects are a really nice solution. But from my experience, never use none FQDN objects that‘s a real performance killer especially if you’re gateways are under attack. To check if a packet matches a rule with none FQDN object a reverse DNS request will be need. These slow down everything. I‘m surprised&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;is happy with such a configuration.&lt;/P&gt;
&lt;P&gt;There are a lot of additional objects to be used as dynamic sources or destinations. Have a look at&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;nice presentation from CPX 360&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Member-Exclusive-Content/Check-Point-dynamic-Object-Types-amp-Typical-Use-Cases/m-p/139701#M87" target="_blank" rel="noopener"&gt;Check Point “dynamic” Object Types &amp;amp; Typical Use Cases&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2022 19:52:33 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-04-07T19:52:33Z</dc:date>
    <item>
      <title>Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145713#M23007</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;We are getting more and more requests for adding firewalls rules in that go to domains that use cdn's or go to multiple different ip's etc.&lt;/P&gt;&lt;P&gt;This is causing us a real pain.&lt;/P&gt;&lt;P&gt;What can we do about this? can we use dns based objects? I know this used to cause issues a long time ago, has Checkpoint now got a better solution for this?&lt;/P&gt;&lt;P&gt;how should I solve it?&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 13:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145713#M23007</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-04-07T13:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145753#M23038</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27524"&gt;@carl_t&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you already using Domain Objects (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120633&amp;amp;t=1649359067432" target="_blank" rel="noopener"&gt;SK120633&lt;/A&gt;&amp;nbsp;) in your rulebase? We are running R80.40 gateway &amp;amp; management with FQDN &amp;amp; non-FQDN domain objects in our rulebase and they work great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regardless of whether the domain resolves to one IP or multiple IPs, the gateway will allow the connection based on the IP of the DNS lookup from the domain objects.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 19:24:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145753#M23038</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-04-07T19:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145766#M23039</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27524"&gt;@carl_t&lt;/a&gt;&amp;nbsp;Domain Objects are a really nice solution. But from my experience, never use none FQDN objects that‘s a real performance killer especially if you’re gateways are under attack. To check if a packet matches a rule with none FQDN object a reverse DNS request will be need. These slow down everything. I‘m surprised&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;is happy with such a configuration.&lt;/P&gt;
&lt;P&gt;There are a lot of additional objects to be used as dynamic sources or destinations. Have a look at&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;nice presentation from CPX 360&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Member-Exclusive-Content/Check-Point-dynamic-Object-Types-amp-Typical-Use-Cases/m-p/139701#M87" target="_blank" rel="noopener"&gt;Check Point “dynamic” Object Types &amp;amp; Typical Use Cases&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 19:52:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145766#M23039</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-07T19:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145767#M23040</link>
      <description>&lt;P&gt;I agree with the guys. The sk&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;provided you is really good reference. I also use those for another customer and they never had a problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 20:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145767#M23040</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-07T20:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145772#M23042</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have very few non-FQDN domain objects in our firewall, but you're right, having a lot of them would impact performance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the dynamic objects info - very useful!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 21:10:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145772#M23042</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-04-07T21:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145773#M23043</link>
      <description>&lt;P&gt;From my experience, anything up to 200 is ok...more than that, could be a problem.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 21:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145773#M23043</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-07T21:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145776#M23045</link>
      <description>&lt;P&gt;Thanks for the tip &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that non-FQDN you're referring to?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 21:33:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145776#M23045</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-04-07T21:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Domain based objects - what is the solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145777#M23046</link>
      <description>&lt;P&gt;For you, no charge :). And yes, thats what I was referring to!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 21:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-based-objects-what-is-the-solution/m-p/145777#M23046</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-07T21:48:33Z</dc:date>
    </item>
  </channel>
</rss>

