<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162951#M29044</link>
    <description>&lt;P&gt;It sounds like you have some performance issues, is this correct? What is the average CPU utilization on the GW?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 15:04:34 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-11-23T15:04:34Z</dc:date>
    <item>
      <title>FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup Rul</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162919#M29040</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using Gateway on the AWS, Version is R80.40 and we are facing a Strange issue that, the rules which are created on the Basis of FQDN's are not getting Matched on the firewall, traffic is getting drop&amp;nbsp; by Clean up rule. We did following.&lt;/P&gt;&lt;P&gt;1. Failover.&lt;/P&gt;&lt;P&gt;2. Reboot both the firewalls.&lt;/P&gt;&lt;P&gt;3. DNS Cache increment of the Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need expert Guidance on this to proceed further.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To mitigate this Situation we are creating IP Based rule and it works fine.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:00:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162919#M29040</guid>
      <dc:creator>Vikaspathak022</dc:creator>
      <dc:date>2022-11-23T12:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162941#M29041</link>
      <description>&lt;P&gt;Before anything else, check if your FW can resolve those FQDN objects into IPs by names&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 13:43:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162941#M29041</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-23T13:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162942#M29042</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;brings up very logical point indeed, If what he says fails, then it would make sense why you have this issue.&lt;/P&gt;
&lt;P&gt;Can you run below and see what you get? Below is an example from my lab. This is brand new R81.20 lab, but output would look pretty much the same on any version.&lt;/P&gt;
&lt;P&gt;[Expert@quantum_gateway:0]# curl_cli -k google.com&lt;BR /&gt;&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&amp;lt;meta http-equiv="content-type" content="text/html;charset=utf-8"&amp;gt;&lt;BR /&gt;&amp;lt;TITLE&amp;gt;301 Moved&amp;lt;/TITLE&amp;gt;&amp;lt;/HEAD&amp;gt;&amp;lt;BODY&amp;gt;&lt;BR /&gt;&amp;lt;H1&amp;gt;301 Moved&amp;lt;/H1&amp;gt;&lt;BR /&gt;The document has moved&lt;BR /&gt;&amp;lt;A HREF="&lt;A href="http://www.google.com/" target="_blank"&gt;http://www.google.com/&lt;/A&gt;"&amp;gt;here&amp;lt;/A&amp;gt;.&lt;BR /&gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;BR /&gt;[Expert@quantum_gateway:0]#&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 13:47:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162942#M29042</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-23T13:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162944#M29043</link>
      <description>&lt;P&gt;Well Yes its happening from the firewall, Firewall can resolve the domain names, infect, its working in the rules also, but some times we can see drops on the firewall on the cleanup rule and sometimes we can its getting allowed on the rule created for the traffic.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;curl_cli -k google.com: What is impact of this, our environment is bit critical and unstable to do such tests, normal nslookup i did and it worked.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 14:14:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162944#M29043</guid>
      <dc:creator>Vikaspathak022</dc:creator>
      <dc:date>2022-11-23T14:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162951#M29044</link>
      <description>&lt;P&gt;It sounds like you have some performance issues, is this correct? What is the average CPU utilization on the GW?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 15:04:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162951#M29044</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-23T15:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162954#M29045</link>
      <description>&lt;P&gt;Are clients using the same DNS resolution path as the firewalls? My bet is they're not, and the clients are getting different IPs back from DNS.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 15:19:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162954#M29045</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-11-23T15:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162957#M29046</link>
      <description>&lt;P&gt;Avg Utilization of the Firewalls are ~ 30 to 35% and clients are also have the same DNS and they are working fine. This issue with the Firewalls also is intermittent.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 15:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162957#M29046</guid>
      <dc:creator>Vikaspathak022</dc:creator>
      <dc:date>2022-11-23T15:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162963#M29047</link>
      <description>&lt;P&gt;CPU is between 30 to 35%, Hosts are also having the Same DNS configured but they are not facing any issue.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 16:28:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162963#M29047</guid>
      <dc:creator>Vikaspathak022</dc:creator>
      <dc:date>2022-11-23T16:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162975#M29048</link>
      <description>&lt;P&gt;I'd try applying the current recommended JHF for R80.40.&lt;BR /&gt;If you're still having issues, a TAC case is probably warranted.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 18:57:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/162975#M29048</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-23T18:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163008#M29049</link>
      <description>&lt;P&gt;Are the hosts behind the gateways using the same DNS server(s) as the gateways?&lt;/P&gt;&lt;P&gt;I had a scenario once where the DNS servers were not the same and with load balanced public servers different DNS servers would return different results for the same FQDN.&lt;/P&gt;&lt;P&gt;once I configured my gateways to use the same DNS servers as the hosts behind them the FQDN’s resolved to the same IP &amp;nbsp;and the intended rule was matched every time.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 01:20:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163008#M29049</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2022-11-24T01:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163027#M29056</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3929"&gt;@Mike_Jensen&lt;/a&gt;&amp;nbsp;Well, How this can be possible in the Global Infra, as these gateways are in the AWS DC, and users globally are coming to the Central DC, we can not have a central DNS for all the global Users, and the user who are having the Similar DNS as gateway also face this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;can you please share any link or SK for the JHF.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 08:27:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163027#M29056</guid>
      <dc:creator>Vikaspathak022</dc:creator>
      <dc:date>2022-11-24T08:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163081#M29064</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/R80.40_Downloads.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/R80.40_Downloads.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 15:31:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163081#M29064</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-24T15:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163469#M29189</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;for the suggestion, we have performed the same thing on our firewalls, moved firewall from Take 119 JHF to 180 JHF, but problem still persists, looking for more guidance.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 08:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163469#M29189</guid>
      <dc:creator>Vikaspathak022</dc:creator>
      <dc:date>2022-11-29T08:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Rules are not getting matched and traffic is getting dropped on the Firewall, under Cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163561#M29213</link>
      <description>&lt;P&gt;Recommend engaging with the TAC to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:22:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Rules-are-not-getting-matched-and-traffic-is-getting/m-p/163561#M29213</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-29T14:22:50Z</dc:date>
    </item>
  </channel>
</rss>

