<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain object FQDN not matching properly in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189712#M34954</link>
    <description>&lt;P&gt;I've opened ticket, thanks.&lt;/P&gt;&lt;P&gt;Maybe it is a bug.&lt;/P&gt;&lt;P&gt;I will share if CP team will give me the solution.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2023 05:42:32 GMT</pubDate>
    <dc:creator>nemezis_rock</dc:creator>
    <dc:date>2023-08-17T05:42:32Z</dc:date>
    <item>
      <title>Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189553#M34913</link>
      <description>&lt;P&gt;Hi dears,&lt;/P&gt;&lt;P&gt;R81.10 JHT 109&lt;/P&gt;&lt;P&gt;A month ago I was testing Reverse Proxy usage. And it worked great with Access Policy.&lt;/P&gt;&lt;P&gt;My test Reverse Proxy rules were like this:&lt;/P&gt;&lt;P&gt;rule1 |&amp;nbsp; &lt;A href="https://test1.domain.example/" target="_blank" rel="noopener"&gt;https://test1.domain.example/&lt;/A&gt; -&amp;gt; &lt;A href="http://192.168.10.0/" target="_blank" rel="noopener"&gt;http://192.168.10.10/&lt;/A&gt;&lt;BR /&gt;rule2 |&amp;nbsp; &lt;A href="https://test2.domain.example/" target="_blank" rel="noopener"&gt;https://test2.domain.example/&lt;/A&gt;&amp;nbsp;-&amp;gt; &lt;A href="http://192.168.20.20/" target="_blank" rel="noopener"&gt;http://192.168.20.20/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Test Security Access Rules were:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;AccRule1&lt;/FONT&gt;&lt;BR /&gt;Source: &lt;FONT color="#3366FF"&gt;ExternalIP1&lt;/FONT&gt;&lt;BR /&gt;Dst: &lt;FONT color="#3366FF"&gt;.test1.domain.example&lt;/FONT&gt; (Domain Object FQDN)&lt;BR /&gt;Service: HTTPS&lt;BR /&gt;Action: Accept&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;AccRule2&lt;/FONT&gt;&lt;BR /&gt;Source: &lt;FONT color="#FF0000"&gt;ExternalIP2&lt;/FONT&gt;&lt;BR /&gt;Dst: .&lt;FONT color="#FF0000"&gt;test2.domain.example&lt;/FONT&gt; (Domain Object FQDN)&lt;BR /&gt;Service: HTTPS&lt;BR /&gt;Action: Accept&lt;/P&gt;&lt;P&gt;And it worked fine that time! &lt;FONT color="#3366FF"&gt;ExternalIP1&lt;/FONT&gt; was accessing &lt;FONT color="#3366FF"&gt;.test1.domain.example&lt;/FONT&gt; and couldnt access to &lt;FONT color="#FF0000"&gt;.test2.domain.example&lt;/FONT&gt;. All other external requests to my domain were dropping by cleanup rule.&lt;/P&gt;&lt;P&gt;But now Firewall stopped matching FQDNs. When &lt;FONT color="#3366FF"&gt;ExternalIP1 &lt;/FONT&gt;is connecting to &lt;FONT color="#FF0000"&gt;.test2.domain.example&amp;nbsp;&lt;FONT color="#000000"&gt;&lt;FONT color="#333333"&gt;it passess traffic&lt;/FONT&gt; via&amp;nbsp;&lt;FONT color="#3366FF"&gt;AccRule1&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT color="#333333"&gt;and according to Logs destination shown as&amp;nbsp;&lt;/FONT&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#3366FF"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#3366FF"&gt;.test1.domain.example&lt;FONT color="#000000"&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT color="#333333"&gt; It is not resolving FQDN.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333333"&gt;Any suggestions?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333333"&gt;Thanks in advance.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 20:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189553#M34913</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-08-15T20:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189564#M34918</link>
      <description>&lt;P&gt;Have you done any troubleshooting with the domains tool?&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk161632" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk161632&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 21:56:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189564#M34918</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-15T21:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189568#M34919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Domain Object is resolving fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;domains_tool -report - gave just&amp;nbsp;Undefined DNS servers found.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The issue is that Firewall blade matching FQDN of second.domain.example as first.domain.example. It sees not as second.domain but as first.domain.example - in Logs. First Access Rule contains first.domain.example. And even if there is no access rule for the second.domain.example but Reverse Proxy rule exists, request to second domain passess Firewall as Dst:first.domain.example and then goes to RProxy rule)&lt;/P&gt;&lt;P&gt;So I am a bit confused. It was working fine while testing. But now it just wont.&lt;/P&gt;&lt;P&gt;Look at the screenshot:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rpx.png" style="width: 742px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22071iC738233C5878B1A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="rpx.png" alt="rpx.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Access rule has only one service (8001) that's hidden behind RProxy and first FQDN but it forwards it to two services (8001 and 8003) because the second FQDN recognized as first and passed to PRoxy rule for 8003 service.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 22:32:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189568#M34919</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-08-15T22:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189631#M34941</link>
      <description>&lt;P&gt;When you say Reverse Proxy, you mean this functionality?&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk110348" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk110348&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regardless, you’ll probably need to consult with the TAC on this: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 15:58:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189631#M34941</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-16T15:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189712#M34954</link>
      <description>&lt;P&gt;I've opened ticket, thanks.&lt;/P&gt;&lt;P&gt;Maybe it is a bug.&lt;/P&gt;&lt;P&gt;I will share if CP team will give me the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 05:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189712#M34954</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-08-17T05:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189716#M34956</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96959"&gt;@nemezis_rock&lt;/a&gt;&amp;nbsp;this looks like a follow up of your formerly post&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Implied-Rules-accepting-HTTP-HTTPS-traffic-How-to-disable-that/m-p/186974#M34401" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Implied-Rules-accepting-HTTP-HTTPS-traffic-How-to-disable-that/m-p/186974#M34401&lt;/A&gt;&amp;nbsp;Please have a look at my last comment.&lt;/P&gt;
&lt;P&gt;Does&amp;nbsp;&lt;SPAN&gt;test2.domain.example and&amp;nbsp;test1.domain.example resolve via DNS to the same IP address ? (Should be, because you want to forward these via Reverseproxy)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If yes, you see expected behaviour, because the gateways handles the rule with an domain-object with the DNS resolved IP address and not the FQDN or&amp;nbsp; URL.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 06:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189716#M34956</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-08-17T06:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189735#M34958</link>
      <description>&lt;P&gt;The point is that it was working fine while testing.&lt;/P&gt;&lt;P&gt;Firewall blade saw two FQDNs perfectly. I've created two domain objects pointed to the same GW-Extrernal address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found Logs especially for you)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fqdn1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22111i75479C989263B7AD/image-size/large?v=v2&amp;amp;px=999" role="button" title="fqdn1.png" alt="fqdn1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Two separate external sources - .199 and .66. Look on the Access Rule number. One source goes through rule 5 and another through rule 4.&lt;/P&gt;&lt;P&gt;And here are logs which shows that fqdns is matching perfectly. Firewall blade sees every FQDN:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fqdn2.png" style="width: 386px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22112i94B7EF3C659C484C/image-size/large?v=v2&amp;amp;px=999" role="button" title="fqdn2.png" alt="fqdn2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fqdn3.png" style="width: 389px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22113i93B1484F49117ADA/image-size/large?v=v2&amp;amp;px=999" role="button" title="fqdn3.png" alt="fqdn3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now you see that Firewall Blade saw every FQDN (test123 and asdasd) perfectly even if they were pointed to the same IP .30.&lt;/P&gt;&lt;P&gt;That is my problem. Firewall Blade forgot how to do it)&lt;/P&gt;&lt;P&gt;By your logic, logs must show only one fqdn, and acces only via one rule. That is happening now. But back then... So i think we have to remind Firewall how to do it.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 09:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189735#M34958</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-08-17T09:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189762#M34959</link>
      <description>&lt;P&gt;I read all your responses and they all seem 100% logical to me. Let us know what TAC says.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 12:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189762#M34959</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-17T12:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object FQDN not matching properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189774#M34964</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96959"&gt;@nemezis_rock&lt;/a&gt;&amp;nbsp;I think the different log entries are an result of the name resolution in SmartDashboard or/and logserver.&lt;/P&gt;
&lt;P&gt;But again, if both FQDNs points to the same IP address I'm pretty sure you can't achieve this way what you want.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 13:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-object-FQDN-not-matching-properly/m-p/189774#M34964</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-08-17T13:53:42Z</dc:date>
    </item>
  </channel>
</rss>

