<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS trap always shows same domain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161664#M28648</link>
    <description>&lt;P&gt;I run into a post somewhere (can't remember exactly where) that said that a cpstop;cpstart on SMS could resolve the issue.&lt;/P&gt;&lt;P&gt;Today we performed a hotfix installation on our SMS and currently we aren't facing the issue with the DNS trap.&lt;/P&gt;&lt;P&gt;Lets hope it fixed it!&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2022 11:19:34 GMT</pubDate>
    <dc:creator>kadar2</dc:creator>
    <dc:date>2022-11-09T11:19:34Z</dc:date>
    <item>
      <title>DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160818#M28383</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few weeks ago, a suspicious communication towards the domain “4s.pm” was identified by Anti-Virus blade and DNS trap was successfully enforced.&lt;/P&gt;&lt;P&gt;Since then, what we notice and we can not explain is the fact that if we search for “DNS Trap” &lt;STRONG&gt;all the results&lt;/STRONG&gt; refer as destination “4s.pm” (screenshot 1). This is weird and most possibly false because if we randomly open one of these logs (Screenshot 2), in the forensics section the actual domain is referred and it is not “4s.pm”.&lt;/P&gt;&lt;P&gt;Can somebody help us understand the behavior?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 12:08:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160818#M28383</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2022-10-31T12:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160830#M28387</link>
      <description>&lt;P&gt;Refer to how the DNS Trap works here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk74060&amp;amp;partition=Basic&amp;amp;product=Anti-Virus" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk74060&amp;amp;partition=Basic&amp;amp;product=Anti-Virus&lt;/A&gt;&lt;BR /&gt;The IP address listed (62.0.58.94) is the default configuration for DNS Trap and is expected behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 13:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160830#M28387</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-31T13:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160890#M28399</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;/P&gt;&lt;P&gt;the question isn't related to the IP 62.0.58.94, which is the default DNS trap.&lt;/P&gt;&lt;P&gt;We do not have any actual traffic that is trying to reach 4s.pm (only one incident about a month ago). No DNS requests towards 4s.pm are logged in our DNS servers. So it is confusing to see this domain in the DNS trap logs. As you can see in the "screenshot2" the forensics details --&amp;gt; resource refers to a totally different domain. So why isn't the actual domain (digitaloceans.com in our example) translated to 62.0.58.94?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 07:04:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160890#M28399</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2022-11-01T07:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160929#M28410</link>
      <description>&lt;P&gt;If you create a dummy object in your DB (example name: cp-dns-trap) for that IP does it make it clearer in the logs?&lt;/P&gt;
&lt;P&gt;Alternatively you can disable object resolution with Ctrl-r or change the DNS trap IP.&lt;/P&gt;
&lt;P&gt;Refer also:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/SMS-log-incorrect-name-resolution/td-p/128459" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Management/SMS-log-incorrect-name-resolution/td-p/128459&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 15:36:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/160929#M28410</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-01T15:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161561#M28606</link>
      <description>&lt;P&gt;We actually opened a TAC case and we are awaiting on feedback.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 13:29:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161561#M28606</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2022-11-08T13:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161581#M28614</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also try adjusting the DNS cache, but that's probably the extent of it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/SMS-log-incorrect-name-resolution/td-p/128459#M31568" target="_blank"&gt;https://community.checkpoint.com/t5/Management/SMS-log-incorrect-name-resolution/td-p/128459#M31568&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 13:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161581#M28614</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-08T13:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap always shows same domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161664#M28648</link>
      <description>&lt;P&gt;I run into a post somewhere (can't remember exactly where) that said that a cpstop;cpstart on SMS could resolve the issue.&lt;/P&gt;&lt;P&gt;Today we performed a hotfix installation on our SMS and currently we aren't facing the issue with the DNS trap.&lt;/P&gt;&lt;P&gt;Lets hope it fixed it!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 11:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-trap-always-shows-same-domain/m-p/161664#M28648</guid>
      <dc:creator>kadar2</dc:creator>
      <dc:date>2022-11-09T11:19:34Z</dc:date>
    </item>
  </channel>
</rss>

