<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS bad TCP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187532#M34595</link>
    <description>&lt;P&gt;How does your version/JHF compare to that listed in the previous similar threads?&lt;/P&gt;
&lt;P&gt;I see two SR's with similar symptoms but the cause was undetermined in each.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2023 14:22:02 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-07-25T14:22:02Z</dc:date>
    <item>
      <title>DNS bad TCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187486#M34593</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We pointing DNS IP address for our VPN Pool IP to internal windows DNS server. When i check log on the windows dns server i got many warning 'The DNS server received a bad TCP-based DNS message from 10.103.254.6. The packet was rejected or ignored. The event data contains the DNS packet.'&lt;/P&gt;&lt;P&gt;IP 10.103.254.6 is our checkpoint.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:11:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187486#M34593</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-07-25T12:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS bad TCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187522#M34594</link>
      <description>&lt;P&gt;Has also been dicussed her without a solution: &lt;A href="https://community.checkpoint.com/t5/General-Topics/Internal-DNS-was-flooded-by-bad-TCP-based-DNS-from-Check-Point/m-p/178083#M29652" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Internal &lt;STRONG&gt;DNS&lt;/STRONG&gt; was flooded by &lt;STRONG&gt;bad&lt;/STRONG&gt; &lt;STRONG&gt;TCP-based&lt;/STRONG&gt; &lt;STRONG&gt;DNS&lt;/STRONG&gt; from Check Point&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 13:37:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187522#M34594</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-25T13:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS bad TCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187532#M34595</link>
      <description>&lt;P&gt;How does your version/JHF compare to that listed in the previous similar threads?&lt;/P&gt;
&lt;P&gt;I see two SR's with similar symptoms but the cause was undetermined in each.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 14:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187532#M34595</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-25T14:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNS bad TCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187535#M34596</link>
      <description>&lt;P&gt;I would contact TAC about this, honestly. I checked support site and literally only things that show up are community posts and specifically one that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;pointed to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 14:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187535#M34596</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T14:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: DNS bad TCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187615#M34598</link>
      <description>&lt;P&gt;i using version 81.10 with JHF 87&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 01:13:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187615#M34598</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-07-26T01:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS bad TCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187616#M34599</link>
      <description>&lt;P&gt;on the sk 133313 there are 2 solution :&lt;/P&gt;&lt;P&gt;1. disable '&lt;SPAN&gt;Log implied rules', i check this already&amp;nbsp;disabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Change&amp;nbsp;&lt;EM&gt;rad_kernel_domain_cache_refresh_interval&lt;/EM&gt;&amp;nbsp; and&amp;nbsp;&lt;EM&gt;rad_kernel_domain_cache_ip_success_lookup_timeout.&amp;nbsp;&lt;/EM&gt;What value is recommended&amp;nbsp;for both parameters?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 01:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-bad-TCP/m-p/187616#M34599</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-07-26T01:16:50Z</dc:date>
    </item>
  </channel>
</rss>

