<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updatable Objects contain non-FQDN Domain objects?! -&amp;gt; decrease performance significantly! in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181421#M33196</link>
    <description>&lt;P&gt;How did you measure this performance decrease ? I read that &lt;EM&gt;This can decrease&lt;/EM&gt;&amp;nbsp; - so it is not inevitable. And &lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk161612: Domain Object Enhancement - DNS Passive Learning&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;gives other insights...&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 08:52:16 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-05-19T08:52:16Z</dc:date>
    <item>
      <title>Updatable Objects contain non-FQDN Domain objects?! -&gt; can decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181417#M33194</link>
      <description>&lt;P&gt;stumbled on this &lt;A href="https://support.checkpoint.com/results/sk/sk162577" target="_self"&gt;sk162577 &lt;/A&gt;&amp;nbsp;lately about non-FQDN Domain object causing "d&lt;SPAN&gt;ecrease the performance of the Security Gateway significantly" ...this sent my on my quest to eleminate non-FQDN Domain Objects in my rulebase...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;to get rid of non-FQDN Domain Objects i used "Updatable Objects" like:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check Point Services&lt;/LI&gt;&lt;LI&gt;Microsoft Updates - HTTPS bypass&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;but today i found this&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk90401" target="_self"&gt;sk90401&lt;/A&gt;&amp;nbsp;which gives me the command:&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;fw ctl multik print_bl dns_reverse_unmatched_cache&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;dns_reverse_unmatched_cache&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;table keeps the IP addresses that are not matched to any of the domain objects in the policy (&lt;STRONG&gt;the table is filled only if you have at least one non-FQDN object in the policy&lt;/STRONG&gt;).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;...so according to this i use non-FQDN Domain objects...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;so after a bit of research i found this nice command to list the content of "Updatabel Object" in another &lt;A href="https://support.checkpoint.com/results/sk/sk161632" target="_self"&gt;sk161632&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;&lt;PRE&gt;domains_tool -uo "Microsoft Updates - HTTPS bypass"&lt;/PRE&gt;&lt;P&gt;and this gives the following output:&lt;/P&gt;&lt;PRE&gt;Domains name list for 'Microsoft Updates - HTTPS bypass':&lt;BR /&gt;&lt;BR /&gt;[1] tsfe.trafficshaping.dsp.mp.microsoft.com&lt;BR /&gt;[2] &lt;STRONG&gt;*.delivery.mp.microsoft.com&lt;/STRONG&gt;&lt;BR /&gt;[3] &lt;STRONG&gt;*.vortex-win.data.microsoft.com&lt;/STRONG&gt;&lt;BR /&gt;[4] login.live.com&lt;BR /&gt;[5] settings-win.data.microsoft.com&lt;BR /&gt;[6] sls.update.microsoft.com&lt;BR /&gt;[7] update.microsoft.com&lt;BR /&gt;[8] &lt;STRONG&gt;*.update.microsoft.com&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;...even the "Check Point Services" hat&amp;nbsp;*.maas.checkpoint.com in it!!!&lt;/P&gt;&lt;P&gt;so to sum it up:&lt;/P&gt;&lt;P&gt;DO NOT USE "Updatable Objects" because they will "&lt;SPAN&gt;decrease the performance of the Security Gateway significantly" (according to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk162577" target="_self"&gt;sk162577&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;@Checkpoint: why do you use non-FQDN in "Updatable Objects" ???!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 09:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181417#M33194</guid>
      <dc:creator>GHaider</dc:creator>
      <dc:date>2023-05-19T09:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181421#M33196</link>
      <description>&lt;P&gt;How did you measure this performance decrease ? I read that &lt;EM&gt;This can decrease&lt;/EM&gt;&amp;nbsp; - so it is not inevitable. And &lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk161612: Domain Object Enhancement - DNS Passive Learning&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;gives other insights...&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 08:52:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181421#M33196</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-19T08:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181424#M33198</link>
      <description>&lt;P&gt;yes you are right, it "can" decrease... would be nice if we can find out when this is the case... measuring the difference is not that simple in my case, a lot of work to do to eliminate the updatable objects (with non-FQDN in it)&lt;/P&gt;&lt;P&gt;...and up to today, i did not have a performance issue with the non-FQDN Domain objects (but i have DNS Passive Learning enabled), so hope it stays that way...&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 09:21:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181424#M33198</guid>
      <dc:creator>GHaider</dc:creator>
      <dc:date>2023-05-19T09:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181426#M33199</link>
      <description>&lt;P&gt;Open a informational SR# with TAC - even sk162577 suggests to refer to TAC...&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 10:25:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181426#M33199</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-19T10:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; can decrease performance significantly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181457#M33207</link>
      <description>&lt;P&gt;The SK refers to a specific object type: Domain objects configured with a non FQDN.&lt;BR /&gt;These types of objects have been around since the earliest versions of Check Point and &lt;SPAN&gt;require a reverse DNS lookup (IP to name), which doesn’t usually provide an appropriate result anyway (eg if the service is hosted in AWS or similar).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This SK does not apply to our Updatable Objects, ioc_feeds, or other places where a wildcard FQDN is used.&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 12:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181457#M33207</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-19T12:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; can decrease performance significantly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181461#M33208</link>
      <description>&lt;P&gt;I had done this, cant even count how many times, never had a single problem.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 13:18:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/181461#M33208</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-19T13:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/198681#M37210</link>
      <description>&lt;P&gt;hello Buddy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you explain how exactly "DNS passive learning" helps in a situation where there is no Reverse DNS entry for non-FQDN domain object ?&lt;/P&gt;
&lt;P&gt;does the new custom updatable object in R81 is the generic datacenter ? and how is it different from network feed object apart from the flat option available on the last ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:22:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/198681#M37210</guid>
      <dc:creator>faridb</dc:creator>
      <dc:date>2023-11-22T15:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/198684#M37212</link>
      <description>&lt;P&gt;Generic data objects allow you to block known bad IP addresses using json format. Network feed works with both combo IP/fqdn as well. As far as say indicators, thats mostly used when AV blade is enabled to block pages, similar to how you would do using combination of urlf blades and https inspection.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;If you need some examples, I have great lab where all this is enabled and actually working &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 15:39:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/198684#M37212</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-22T15:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; decrease performance significantly!</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/198774#M37227</link>
      <description>&lt;P&gt;If the Security Gateway is in the path between the client and the DNS Server (which must be explicitly configured if it is different from that which the gateway is configured to use), we can use the result of that DNS lookup to populate the cache in the gateway because…the gateway can see it.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 14:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/198774#M37227</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-23T14:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; can decrease performance significantly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/230795#M44431</link>
      <description>&lt;P&gt;So, if we use non-FQDN objects, gateway does ‘reverse DNS queries’ and ‘DNS Passive Learning’. (sk120633)&lt;/P&gt;&lt;P&gt;Reverse DNS queries can cause traffic latency (&lt;SPAN&gt;sk162577&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using non-FQDN objects, is there a way to use only DNS Passive Learning and avoid revers DNS queries?&lt;/P&gt;&lt;P&gt;I mean, I can stop DNS passive Learning but I can’t stop reverse DNS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 10:59:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/230795#M44431</guid>
      <dc:creator>victor_vidal</dc:creator>
      <dc:date>2024-10-25T10:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects contain non-FQDN Domain objects?! -&gt; can decrease performance significantly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/230852#M44443</link>
      <description>&lt;P&gt;I don't believe you can disable the reverse DNS lookups when you use non-FQDN objects.&lt;BR /&gt;It's how those objects are designed to work.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 20:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-contain-non-FQDN-Domain-objects-gt-can/m-p/230852#M44443</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-25T20:06:24Z</dc:date>
    </item>
  </channel>
</rss>

