<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Excessive DNS Queries from Gateways in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201222#M37823</link>
    <description>&lt;P&gt;What appears to be happening is that every time an FQDN rule gets hit, the gateway is looking up the IP rather than using DNS cache.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Dec 2023 17:01:20 GMT</pubDate>
    <dc:creator>timothyjwitt</dc:creator>
    <dc:date>2023-12-20T17:01:20Z</dc:date>
    <item>
      <title>Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201138#M37803</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;We started to see an excessive amount of DNS queries coming from our gateways seemingly looking up FQDN objects.&amp;nbsp; This started 12/17/2023 at 1am and we see it on multiple gateways at multiple sites with different DNS servers in Gaia config.&lt;BR /&gt;When I say excessive, one site 'normal' operation prior to the issue had 92k (10MB) dns queries from the gateway per hour and after this past Sunday it's at 17Million (1.8GB) per hour.&lt;BR /&gt;No changes to the environments since 12/14/2023, we are currently in a code freeze.&lt;BR /&gt;We are on R81.10 JHF 95.&lt;BR /&gt;We have ~580 FQDN objects in policies.&lt;BR /&gt;Policy install didn't fix, nor did failover but a reboot seems to have resolved it.&lt;BR /&gt;Wondering if anyone else has seen anything strange like this.&lt;BR /&gt;TAC has been engaged.&lt;BR /&gt;Thanks,&lt;BR /&gt;Tim&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 21:26:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201138#M37803</guid>
      <dc:creator>timothyjwitt</dc:creator>
      <dc:date>2023-12-19T21:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201160#M37807</link>
      <description>&lt;P&gt;The DNS cache is limited to 25000 entries.&lt;BR /&gt;With that many FQDN objects, it's possible you're exceeding this limit and you may need to adjust it:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk157493" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk157493&lt;/A&gt;&lt;BR /&gt;Otherwise, I suggest involving the TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 02:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201160#M37807</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-20T02:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201205#M37818</link>
      <description>&lt;P&gt;The&amp;nbsp;fw tab -t dns_reverse_cache_tbl command output is completely different on my GW's but if I'm reading that correctly the size (limit) is 28672 and the number of entries is 4114.&amp;nbsp; However, the limit in table.def is set at 25000.&lt;BR /&gt;-------- dns_reverse_cache_tbl --------&lt;BR /&gt;htab_bl, id 35, size 28672, attributes: expire, no links, #vals 4114 #slinks 0&lt;BR /&gt;&lt;BR /&gt;I'm stuck on this occurring across our GW fleet at a specific date and time, seems like some sort of automatic update?&lt;BR /&gt;I've got a case open with TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 15:40:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201205#M37818</guid>
      <dc:creator>timothyjwitt</dc:creator>
      <dc:date>2023-12-20T15:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201211#M37820</link>
      <description>&lt;P&gt;If you've hit the high water mark of 25,000, I believe it will show in the output of&amp;nbsp;&lt;SPAN&gt;fw tab -t dns_reverse_cache_tbl -s.&lt;BR /&gt;That would at least tell us if my theory is correct.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 16:18:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201211#M37820</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-20T16:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201212#M37821</link>
      <description>&lt;P&gt;Looks like peak was 12725&lt;BR /&gt;fw tab -t dns_reverse_cache_tbl -s&lt;BR /&gt;HOST NAME ID #VALS #PEAK #SLINKS&lt;BR /&gt;localhost dns_reverse_cache_tbl 38 12725 0 0&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 16:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201212#M37821</guid>
      <dc:creator>timothyjwitt</dc:creator>
      <dc:date>2023-12-20T16:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201222#M37823</link>
      <description>&lt;P&gt;What appears to be happening is that every time an FQDN rule gets hit, the gateway is looking up the IP rather than using DNS cache.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 17:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201222#M37823</guid>
      <dc:creator>timothyjwitt</dc:creator>
      <dc:date>2023-12-20T17:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive DNS Queries from Gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201226#M37825</link>
      <description>&lt;P&gt;You could try below&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32224" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32224&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 17:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Excessive-DNS-Queries-from-Gateways/m-p/201226#M37825</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T17:45:03Z</dc:date>
    </item>
  </channel>
</rss>

