<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Security Gateway act as DNS Server? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172325#M31317</link>
    <description>&lt;P&gt;Thank yoy&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;. I used&amp;nbsp;&lt;SPAN&gt;dnsmasq and it worked flawlessly.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I read about DNS NAT, but it seemed to complicated&amp;nbsp;for my situation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best regards to both of you.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2023 12:08:06 GMT</pubDate>
    <dc:creator>khado</dc:creator>
    <dc:date>2023-02-22T12:08:06Z</dc:date>
    <item>
      <title>Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172138#M31264</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running Security Gateway 81.10, which the main focus is to provide users access directly to internet.&lt;/P&gt;&lt;P&gt;But for a particular reason we need this users to be able to access a server that sits on internal side, using private IPv4 address.&lt;/P&gt;&lt;P&gt;I have activated DNS Server on security gateway object, added the object (e.g. foo.examble.com) at authorization domain list, and protection check on Protected by this machine.&lt;/P&gt;&lt;P&gt;Added the configuration on Hosts via GAIA Web. Allowed the connection for DNS queries from users to securitygateway object for dns quieries, and from logs it seems to be ok.&lt;/P&gt;&lt;P&gt;Changed the DNS servers from DHCP Servers Settings to use the primary DNS the security gateway, and second to use as DNS 1.1.1.1.&lt;/P&gt;&lt;P&gt;and when I try to ping foo.example.com I get a response as below:&lt;/P&gt;&lt;P&gt;*** UnKnown can't find foo.example.com: No response from server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS suffix on Security gateway is example.com, and DNS suffinc for users is guest.example.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 08:56:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172138#M31264</guid>
      <dc:creator>khado</dc:creator>
      <dc:date>2023-02-21T08:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172185#M31274</link>
      <description>&lt;P&gt;The Security Gateway is not a DNS server.&lt;BR /&gt;We can NAT requests from a DNS server if properly configured.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk34295" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk34295&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172185#M31274</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-21T15:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172192#M31280</link>
      <description>&lt;P&gt;Short answer is yes, your fw can be used as dns server, should you do it that way...probably not. I will see if I can find email R&amp;amp;D sent me about it ages ago why you should NOT do this. It had all the super valid/logical points.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:26:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172192#M31280</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-21T15:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172195#M31282</link>
      <description>&lt;P&gt;There is an unsupported way to make the gateway a DNS server using dnsmasq, which is installed in Gaia OS but isn’t used by default.&lt;BR /&gt;Regardless, this isn’t best practice in enterprise networks.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:38:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172195#M31282</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-21T15:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172196#M31283</link>
      <description>&lt;P&gt;Correct!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:46:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172196#M31283</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-21T15:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172213#M31287</link>
      <description>&lt;P&gt;This is what I wrote about the topic back in 2014:&amp;nbsp;&lt;A href="https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/" target="_blank"&gt;https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;I checked R81.20 and it too has dnsmasq installed on it.&lt;BR /&gt;Haven't tried it to see if it still works...&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 17:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172213#M31287</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-21T17:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172219#M31289</link>
      <description>&lt;P&gt;Not overly shocked its still there : - )&lt;/P&gt;
&lt;P&gt;[Expert@quantum-firewall:0]# service dnsmasq start&lt;BR /&gt;Starting dnsmasq:&lt;BR /&gt;[Expert@quantum-firewall:0]# service dnsmasq stop&lt;BR /&gt;Shutting down dnsmasq: [ OK ]&lt;BR /&gt;[Expert@quantum-firewall:0]# fw ver&lt;BR /&gt;This is Check Point's software version R81.20 - Build 703&lt;BR /&gt;[Expert@quantum-firewall:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 17:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172219#M31289</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-21T17:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172325#M31317</link>
      <description>&lt;P&gt;Thank yoy&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;. I used&amp;nbsp;&lt;SPAN&gt;dnsmasq and it worked flawlessly.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I read about DNS NAT, but it seemed to complicated&amp;nbsp;for my situation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best regards to both of you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 12:08:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/172325#M31317</guid>
      <dc:creator>khado</dc:creator>
      <dc:date>2023-02-22T12:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can Security Gateway act as DNS Server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/219992#M42085</link>
      <description>&lt;P&gt;Interestingly enough, R82 EA not only has dnsmasq installed...it's in use now.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 18:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-Security-Gateway-act-as-DNS-Server/m-p/219992#M42085</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-08T18:22:37Z</dc:date>
    </item>
  </channel>
</rss>

