<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain Object in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190246#M35100</link>
    <description>&lt;P&gt;Hi..&lt;/P&gt;&lt;P&gt;yes, the policy already installed. Also i have another checkpoint and i do test by issuing '&lt;SPAN&gt;domain_tool -d&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.detik.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;www.detik.com'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and this checkpoint showing ip address of detik.com but not for my 1st checkpoint.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2023 07:13:22 GMT</pubDate>
    <dc:creator>handiansudianto</dc:creator>
    <dc:date>2023-08-23T07:13:22Z</dc:date>
    <item>
      <title>Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190081#M35062</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I make a test rule to allowing one server access to ww.detik.com, i create domain object with .detik.com&lt;/P&gt;&lt;P&gt;But i think the domain object is not working, the server still can't access to the &lt;A href="http://www.detik.com," target="_blank" rel="noopener"&gt;www.detik.com,&lt;/A&gt;&amp;nbsp;tick and untick the FQDN on the domain object not helping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone know how about this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 08:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190081#M35062</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-22T08:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190082#M35063</link>
      <description>&lt;P&gt;As you do not show the rule created and the object in detail it is very hard to help here. Did you follow &lt;A href="https://support.checkpoint.com/results/sk/sk120633" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk120633&lt;/A&gt; ? Also read &lt;A href="https://support.checkpoint.com/results/sk/sk90401" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk90401&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 08:45:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190082#M35063</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-22T08:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190093#M35064</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes l already follow the reference article, and here i send my rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="cp1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22159i5FE86F4CCEBC6B02/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp1.JPG" alt="cp1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ticked or not the rule is not working&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="cp2.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22160iC10B26AE16DC9A89/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp2.JPG" alt="cp2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="CP3.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22161iCA5540B3120DFA09/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CP3.JPG" alt="CP3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="cp4.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22162iB93ABE6CA6A4EB2B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp4.JPG" alt="cp4.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 09:01:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190093#M35064</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-22T09:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190094#M35065</link>
      <description>&lt;P&gt;And which rule does match and drop the traffic, cleanup rule ? Why do you use Any service for the rule ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 09:16:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190094#M35065</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-22T09:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190145#M35077</link>
      <description>&lt;P&gt;Non-FQDN objects require the ability to reverse-resolve the IP address to the relevant domain.&lt;BR /&gt;FQDN objects require a forward lookup on the relevant FQDN.&lt;BR /&gt;Have you confirmed the gateway can actually do this?&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk161632" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk161632&lt;/A&gt;&amp;nbsp;(to troubleshoot)&lt;BR /&gt;Maybe also see if the following will help:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk161612&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 13:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190145#M35077</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-22T13:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190210#M35093</link>
      <description>&lt;P&gt;Yes the traffic dropped by cleanup rule. Since i only need the server access to some websites so i set the service as 'Any'.&lt;/P&gt;&lt;P&gt;It's wrong?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 00:39:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190210#M35093</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-23T00:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190213#M35094</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes the gateway can do forward lookup.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp5.JPG" style="width: 823px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22173i6B436E10D1138BBE/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp5.JPG" alt="cp5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When issuing command domain_tool -d &lt;A href="http://www.detik.com" target="_blank"&gt;www.detik.com&lt;/A&gt;&amp;nbsp;i got 'Domain is not attached to any IP address'&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp6.JPG" style="width: 464px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22174i95EC3B86D9847732/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp6.JPG" alt="cp6.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 00:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190213#M35094</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-23T00:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190244#M35099</link>
      <description>&lt;P&gt;Is the source IP of the server also correct?&lt;BR /&gt;Recent policy install was done too? - Can check with "fw stat" on gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 07:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190244#M35099</guid>
      <dc:creator>Daniel_3</dc:creator>
      <dc:date>2023-08-23T07:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190246#M35100</link>
      <description>&lt;P&gt;Hi..&lt;/P&gt;&lt;P&gt;yes, the policy already installed. Also i have another checkpoint and i do test by issuing '&lt;SPAN&gt;domain_tool -d&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.detik.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;www.detik.com'&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and this checkpoint showing ip address of detik.com but not for my 1st checkpoint.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 07:13:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190246#M35100</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-23T07:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190251#M35103</link>
      <description>&lt;P&gt;Did you already try '&lt;SPAN&gt;domains_tool -report' from&amp;nbsp;sk161632?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 08:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190251#M35103</guid>
      <dc:creator>Daniel_3</dc:creator>
      <dc:date>2023-08-23T08:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190252#M35104</link>
      <description>&lt;P&gt;i got 'WSDNSD and DNS servers are not synchronized' when issuing&amp;nbsp;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;domains_tool -report'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This can be fixed by command below right? Will this command cause a downtime?&lt;/P&gt;&lt;P&gt;cpwd_admin stop -name WSDNSD -path "$FWDIR/bin/wsdnsd" -command "fw kill wsdnsd";&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;cpwd_admin start -name WSDNSD -path "$FWDIR/bin/wsdnsd" -command "wsdnsd"&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 08:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190252#M35104</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-23T08:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190256#M35107</link>
      <description>&lt;P&gt;Restart of WSDNSD only impacts DNS resolution of the firewall itself and no other traffic. If you have multiple domain-objects and updatable objects I would do it outside of business hours (except if all of them don't work, then it does not matter).&lt;/P&gt;&lt;P&gt;If it is just this one domain you can do it any time.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 09:25:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190256#M35107</guid>
      <dc:creator>Daniel_3</dc:creator>
      <dc:date>2023-08-23T09:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190370#M35128</link>
      <description>&lt;P&gt;Recommend engaging with the TAC here: &lt;A href="https://help.checkpoint.com" target="_self"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 19:17:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190370#M35128</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-23T19:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190410#M35142</link>
      <description>&lt;P&gt;After restarting the WSDNSD now the domain object is working, but i still have a question about object domain.&lt;/P&gt;&lt;P&gt;I want to make domain object for this URL&lt;/P&gt;&lt;P&gt;ussus1eastprod.blob.core.windows.net&lt;BR /&gt;ussus2eastprod.blob.core.windows.net&lt;BR /&gt;ussus3eastprod.blob.core.windows.net&lt;BR /&gt;ussus4eastprod.blob.core.windows.net&lt;BR /&gt;wsus1eastprod.blob.core.windows.net&lt;BR /&gt;wsus2eastprod.blob.core.windows.net&lt;/P&gt;&lt;P&gt;and i make domain object with name .blob.core.windows.net and FQDN not ticked. On my mind domain object .blob.core.windows.net can discover all URL above but when i check with command domains_tool -d&amp;nbsp;blob.core.windows.net and i just only get one ip address. Did you know why?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 01:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190410#M35142</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-08-24T01:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190514#M35163</link>
      <description>&lt;P&gt;Because Domain Objects that aren't FQDN rely on reverse DNS to operate.&lt;BR /&gt;When I look up the IP I get for, e.g.&amp;nbsp;&lt;SPAN&gt;wsus2eastprod.blob.core.windows.net, I get an NXDOMAIN (no record found) for the IP that it resolves to.&lt;BR /&gt;Recommend doing this with either a Custom Application/Site or put these hosts in a Network Feed in R81.20+.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 22:01:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Object/m-p/190514#M35163</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-24T22:01:47Z</dc:date>
    </item>
  </channel>
</rss>

