<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: domain objects not always working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193470#M35952</link>
    <description>&lt;P&gt;Ok, understood. Yea, if you are on R80.40, I doubt that sk applies.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2023 11:44:36 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-09-25T11:44:36Z</dc:date>
    <item>
      <title>domain objects not always working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193443#M35936</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have a policy with about 400 FQDN's in it (all FQDN, non are wildcard) R80.40 gateway, R81.10 Manager&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strangely sometimes they do match, using domain tools -d and -ip i can confirm both the source and dest rule are matchings the IP addresses I am seeing in the logs but the traffic is still dropped on the cleanup rule. I would say we have about 90% success rate and 10% failure, rate, often its within the same rule that some traffic will match and some will not (can't find any pattern)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering if there is some sort of cache limit we might be hitting?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;fw tab -t dns_reverse_unmatched_cache -u -f&lt;BR /&gt;Using cptfmt&lt;BR /&gt;Formatting table's data - this might take a while...&lt;/P&gt;
&lt;P&gt;-------- dns_reverse_unmatched_cache --------&lt;BR /&gt;htab_bl, id 7, size 28672, attributes: expire, no links, #vals 0 #slinks 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw ctl multik print_bl dns_reverse_cache_tbl&lt;BR /&gt;-------- dns_reverse_cache_tbl --------&lt;BR /&gt;htab_bl, id 8, size 28672, attributes: expire, no links, #vals 417 #slinks 0&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 00:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193443#M35936</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2023-09-25T00:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: domain objects not always working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193448#M35937</link>
      <description>&lt;P&gt;Had customer with similar issue last year and TAC suggested cloudguard stop and cloudguard start commands on mgmt server and that fixed it. I cant quite connect the dots as to how logically that worked, but it did.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 02:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193448#M35937</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-25T02:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: domain objects not always working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193449#M35938</link>
      <description>&lt;P&gt;thanks was worth a shot, but still doesn't work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did find&amp;nbsp;sk145952 (although resolved)&amp;nbsp; talks about some limitations when domains resolve to the same Ip, we definitely have that, and some IP resolving to multiple domains, but all our rules are allow so I don't think this is relevant.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 04:31:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193449#M35938</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2023-09-25T04:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: domain objects not always working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193470#M35952</link>
      <description>&lt;P&gt;Ok, understood. Yea, if you are on R80.40, I doubt that sk applies.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 11:44:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/domain-objects-not-always-working/m-p/193470#M35952</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-25T11:44:36Z</dc:date>
    </item>
  </channel>
</rss>

