<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain resolving error. Check DNS configuration on the gateway (0) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154678#M26263</link>
    <description>&lt;P&gt;Thanks for the reply.&amp;nbsp; It is interesting.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;nc -z -v 1.1.1.1 53 responds&lt;/P&gt;
&lt;P&gt;nc -z -v -u 1.1.1.1 53&amp;nbsp; = no response.&lt;/P&gt;
&lt;P&gt;Other systems can get to DNS (UDP) for some reason the firewall can't.&amp;nbsp; I'm getting out, nothing coming back.&amp;nbsp; Looking into it...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Aug 2022 20:28:12 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2022-08-07T20:28:12Z</dc:date>
    <item>
      <title>Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/88516#M26206</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;we started receiving the following alerts:&lt;/P&gt;&lt;P&gt;Domain resolving error. Check DNS configuration on the gateway (0)&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1.PNG" style="width: 791px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6748i58806FE289EF0D51/image-dimensions/791x87?v=v2" width="791" height="87" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2.PNG" style="width: 789px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6749i3F9D428D76D0A99F/image-dimensions/789x349?v=v2" width="789" height="349" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found only one sk about the topic&amp;nbsp;&lt;SPAN&gt;sk120558&amp;nbsp;But it doesn't seem to be related to the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we have cluster of Check Point 23500 appliance &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the version is R80.30 jumbo take 155&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we run nslookup from the gw and its look like fine&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;# nslookup google.co.il&lt;BR /&gt;Server: x.x.x.x&lt;BR /&gt;Address: x.x.x.x#53&lt;/P&gt;&lt;P&gt;we also run dig command from gateway&lt;/P&gt;&lt;P&gt;#dig google.com&lt;/P&gt;&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.3.6-P1-RedHat-9.3.6-25.P1.11.cp993000013 &amp;lt;&amp;lt;&amp;gt;&amp;gt; google.com&lt;BR /&gt;;; global options: printcmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 31783&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0&lt;/P&gt;&lt;P&gt;;; QUESTION SECTION:&lt;BR /&gt;;google.com. IN A&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;BR /&gt;google.com. 26 IN A 172.217.171.238&lt;/P&gt;&lt;P&gt;;; Query time: 1 msec&lt;BR /&gt;;; SERVER: x.x.x.x#53(&lt;SPAN&gt;IPv4 address of dns server&lt;/SPAN&gt;)&lt;BR /&gt;;; WHEN: Sun Jun 14 18:37:35 2020&lt;BR /&gt;;; MSG SIZE rcvd: 44&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like for advice on what to do to stop receiving these alerts&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 15:52:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/88516#M26206</guid>
      <dc:creator>barakh</dc:creator>
      <dc:date>2020-06-14T15:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/88557#M26207</link>
      <description>&lt;P&gt;You masked this too well. It is hard to see which layer is complaining. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Please clarify if:&lt;/P&gt;
&lt;P&gt;1. you are using any of domain objects&lt;/P&gt;
&lt;P&gt;2. using proxy on your GW&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 07:09:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/88557#M26207</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-15T07:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/88665#M26208</link>
      <description>&lt;P&gt;we are using updatable objects not&amp;nbsp;&lt;SPAN&gt;domain objects&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;No proxy is used&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 14:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/88665#M26208</guid>
      <dc:creator>barakh</dc:creator>
      <dc:date>2020-06-15T14:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/116961#M26209</link>
      <description>&lt;P&gt;I just encountered this.&amp;nbsp; We are using Domain objects, and they were working fine until last week, when I had to undo &lt;A href="https://layer77.net/2019/11/27/checkpoint-dedicated-management-route/" target="_blank" rel="noopener"&gt;Management vs. Data Plane Separation&lt;/A&gt;&amp;nbsp; in order to get syslogging working via the Mgmt interface.&lt;/P&gt;&lt;P&gt;The root cause was the Network Management -&amp;gt; Topology settings.&amp;nbsp; It appears that whichever interface is being egressed to reach the DNS server must have "Leads to -&amp;gt; Network defined by Routes" in order to reach the DNS server at the data plane level.&lt;/P&gt;&lt;P&gt;When doing a ping, dig, or nslookup via CLI, the Topology settings are not applicable, which explains why those tests work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 16:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/116961#M26209</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2021-04-26T16:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/117291#M26210</link>
      <description>&lt;P&gt;I am having the same issue. A while back working with CP TAC they had asked me to do a get interfaces to resolve a separate issue but since that time onwards we had some wierd issues. I was told to update our version now 80.10 with latest Jumbo Fix.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone found an exact fix to this problem. Top comment seems to be on point but don' understand what the solution was. Thanks for any help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 21:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/117291#M26210</guid>
      <dc:creator>aboo008</dc:creator>
      <dc:date>2021-04-29T21:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154527#M26211</link>
      <description>&lt;P&gt;I am using a domain object actually, zoom.us on this gw and this is the only gw having this issue.&amp;nbsp; &amp;nbsp;I guess I'll just continue to ignore the error/alert, since we are using that object.&lt;/P&gt;
&lt;P&gt;RE: Domain resolving error. Check DNS configuration on the gateway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Version: R81.10 JHF55&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 13:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154527#M26211</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-08-04T13:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154570#M26225</link>
      <description>&lt;P&gt;One thing you should check is that GW can resolve DNS names using both UDP and TCP. Some larger DNS responses that cannot be pushed in single UDP packet will trigger fallback to TCP protocol. Depending on the FW setup TCP lookups might be dropped. And that will result in error above&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 20:48:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154570#M26225</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-08-04T20:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154678#M26263</link>
      <description>&lt;P&gt;Thanks for the reply.&amp;nbsp; It is interesting.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;nc -z -v 1.1.1.1 53 responds&lt;/P&gt;
&lt;P&gt;nc -z -v -u 1.1.1.1 53&amp;nbsp; = no response.&lt;/P&gt;
&lt;P&gt;Other systems can get to DNS (UDP) for some reason the firewall can't.&amp;nbsp; I'm getting out, nothing coming back.&amp;nbsp; Looking into it...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 20:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154678#M26263</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-08-07T20:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154696#M26269</link>
      <description>&lt;P&gt;I would probably put little more effort into it and try actual packet capture for DNS lookups from gateway itself as error itself indicates that gateway is failing to get DNS responses for FQDN object lookups&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 06:16:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-resolving-error-Check-DNS-configuration-on-the-gateway-0/m-p/154696#M26269</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-08-08T06:16:07Z</dc:date>
    </item>
  </channel>
</rss>

