<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain Name based rule doesn't work in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153872#M25909</link>
    <description>&lt;P&gt;Further to &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;suggestion are all gateways running the same JHF level, are the clients also using the same DNS as the gateway?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 15:51:58 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-07-26T15:51:58Z</dc:date>
    <item>
      <title>Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153866#M25904</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;there are serveral gateways 80.40. I've configured some policies with Domain Names. Almost on all FW it works, but doesn't work on one Gateway. It is resolved by gateway, but does not pass through the FW. What is wrong and how to fix it? Thank you!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log1.png" style="width: 873px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17316i5D57C2BA2B648A36/image-size/large?v=v2&amp;amp;px=999" role="button" title="log1.png" alt="log1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 14:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153866#M25904</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-07-26T14:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153871#M25908</link>
      <description>&lt;P&gt;Tick the FQDN box on that object.&lt;BR /&gt;Otherwise, it's a classic Domain object, which actually requires reverse DNS resolution of the IP address(es) in question.&lt;BR /&gt;Those IP addresses do not have a reverse DNS entry, at least as far as I know.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 15:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153871#M25908</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-26T15:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153872#M25909</link>
      <description>&lt;P&gt;Further to &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;suggestion are all gateways running the same JHF level, are the clients also using the same DNS as the gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 15:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153872#M25909</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-26T15:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153875#M25910</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your answer. It did help, but only for some names:&lt;/P&gt;&lt;P&gt;Test-NetConnection -ComputerName mscrl.microsoft.com -port 80&lt;BR /&gt;ComputerName : mscrl.microsoft.com&lt;BR /&gt;RemoteAddress : 152.199.19.160&lt;BR /&gt;RemotePort : 80&lt;BR /&gt;InterfaceAlias : Ethernet0&lt;BR /&gt;SourceAddress : 192.168.30.4&lt;BR /&gt;TcpTestSucceeded : True&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But here is still doesn't work:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Test-NetConnection -ComputerName crl.microsoft.com -port 80&lt;BR /&gt;WARNING: TCP connect to (87.123.248.82 : 80) failed&lt;BR /&gt;WARNING: TCP connect to (87.123.248.32 : 80) failed&lt;BR /&gt;WARNING: Ping to 87.123.248.82 failed with status: TimedOut&lt;BR /&gt;WARNING: Ping to 87.123.248.32 failed with status: TimedOut&lt;BR /&gt;&lt;BR /&gt;ComputerName : crl.microsoft.com&lt;BR /&gt;RemoteAddress : 87.123.248.82&lt;BR /&gt;RemotePort : 80&lt;BR /&gt;InterfaceAlias : Ethernet0&lt;BR /&gt;SourceAddress : 192.168.30.4&lt;BR /&gt;PingSucceeded : False&lt;BR /&gt;PingReplyDetails (RTT) : 0 ms&lt;BR /&gt;TcpTestSucceeded : False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;from my home PC it works:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Test-NetConnection -ComputerName crl.microsoft.com -port 80&lt;BR /&gt;ComputerName : crl.microsoft.com&lt;BR /&gt;RemoteAddress : 89.27.241.11&lt;BR /&gt;RemotePort : 80&lt;BR /&gt;InterfaceAlias : Ethernet&lt;BR /&gt;SourceAddress : 192.168.178.112&lt;BR /&gt;TcpTestSucceeded : True&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 16:39:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153875#M25910</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-07-26T16:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153876#M25911</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;thank you for your answer. Yes, all gateways are the same. We have updated them recently.&lt;/P&gt;&lt;P&gt;No, the clients and gateways are using different DNS, but this isn't a problem for the other gateways&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 16:41:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153876#M25911</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-07-26T16:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153887#M25913</link>
      <description>&lt;P&gt;These objects only work properly if the DNS servers used by the clients and gateway produce the exact same results.&lt;BR /&gt;The easiest way to ensure this is to have the gateways and clients use the same DNS resolver.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 18:25:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/153887#M25913</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-26T18:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/154004#M25997</link>
      <description>&lt;P&gt;Have You been trying Updateable objects?? From my experience it works much more deterministic then working with DomainName object for MS.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MS_Azure_Updateble.png" style="width: 488px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17333i519E4CD32A552FA1/image-size/large?v=v2&amp;amp;px=999" role="button" title="MS_Azure_Updateble.png" alt="MS_Azure_Updateble.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can list or check what domain or what ip object is included using domains_tool:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="domain_tool.png" style="width: 796px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17334i52738632F7286EAE/image-size/large?v=v2&amp;amp;px=999" role="button" title="domain_tool.png" alt="domain_tool.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 14:29:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/154004#M25997</guid>
      <dc:creator>Rafal_N</dc:creator>
      <dc:date>2022-07-27T14:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Name based rule doesn't work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/154540#M26215</link>
      <description>&lt;P&gt;thank you! this is the easiest way!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 14:58:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Name-based-rule-doesn-t-work/m-p/154540#M26215</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-08-04T14:58:40Z</dc:date>
    </item>
  </channel>
</rss>

