<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220849#M42276</link>
    <description>&lt;P&gt;The configuration file is /etc/dnsmasq.conf&lt;BR /&gt;The error message you receive is because &lt;A href="https://thekelleys.org.uk/dnsmasq/doc.html" target="_self"&gt;dnsmasq&lt;/A&gt; is already running (as stated previously).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2024 20:15:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-15T20:15:40Z</dc:date>
    <item>
      <title>DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220610#M42204</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;Sorry if this may sound like a dumb/stupid/silly question (or all 3 together lol), but I had customer ask me something that no one ever asked me in all my years with CP. So, they wanted to know if Check Point has their own DNS servers like Fortinet does that customers could use? Im pretty sure the answer is no, as I had never seen or heard of any, but wanted to be 100% sure.&lt;/P&gt;
&lt;P&gt;Below is what Im referring to on Fortigates.&lt;/P&gt;
&lt;P&gt;Best and thanks as always for the help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26768i66AAF3F1652E9B58/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 21:27:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220610#M42204</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-12T21:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220637#M42206</link>
      <description>&lt;P&gt;As I suspected, the answer is no, SE also confirmed the same.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 13:32:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220637#M42206</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-13T13:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220673#M42217</link>
      <description>&lt;P&gt;Officially, no.&lt;BR /&gt;However, dnsmasq has been unofficially on Gaia OS for quite some time.&lt;BR /&gt;I even wrote something about it a decade ago (including how to use it):&amp;nbsp;&lt;A href="https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/" target="_blank" rel="noopener"&gt;https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/&lt;/A&gt;&lt;BR /&gt;In the R82 EA, I noticed it’s actually running.&lt;BR /&gt;Not sure what it is officially used for as I haven’t dug into it.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 16:14:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220673#M42217</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-14T16:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220674#M42218</link>
      <description>&lt;P&gt;Funny you gave that link, as I was reading it before making the post and even customer told me about it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Will test in in R82 lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 16:20:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220674#M42218</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-14T16:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220796#M42257</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ran the commands, but not working, definitely missing something brother...any idea? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@R82-TEST-FW:0]# dbset process:dnsmasq t&lt;BR /&gt;[Expert@R82-TEST-FW:0]# dbset process:dnsmasq:path /usr/sbin&lt;BR /&gt;[Expert@R82-TEST-FW:0]# dbset process:dnsmasq:runlevel 3&lt;BR /&gt;[Expert@R82-TEST-FW:0]# dbset :save&lt;BR /&gt;[Expert@R82-TEST-FW:0]# dnsmasq&lt;/P&gt;
&lt;P&gt;dnsmasq: failed to create listening socket for 127.0.0.1: Address already in use&lt;BR /&gt;[Expert@R82-TEST-FW:0]# fw ver -k&lt;BR /&gt;This is Check Point's software version R82 - Build 760&lt;BR /&gt;kernel: R82 - Build 735&lt;BR /&gt;[Expert@R82-TEST-FW:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 14:19:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220796#M42257</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-15T14:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220802#M42261</link>
      <description>&lt;P&gt;Would love to see CP come out with a product like "Meta IP" again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as free DNS services that provide security, Quad9 is still the best.&amp;nbsp; Recently saw some C2 Beacons trying to be accessed.&amp;nbsp; Quad9 was the only provider already blocking the domains.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 14:49:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220802#M42261</guid>
      <dc:creator>John-Haynes</dc:creator>
      <dc:date>2024-07-15T14:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220803#M42262</link>
      <description>&lt;P&gt;Quad 9? Never heard of it, but reading about it, seems like its fantastic, awesome reviews...will let the customer know.&lt;/P&gt;
&lt;P&gt;THANK YOU!!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 14:52:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220803#M42262</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-15T14:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220834#M42269</link>
      <description>&lt;P&gt;Like I said, dnsmasq is &lt;STRONG&gt;&lt;U&gt;&lt;EM&gt;already running&lt;/EM&gt;&lt;/U&gt;&lt;/STRONG&gt; on R82 (no need to enable it).&lt;BR /&gt;Version string says is 2.76.&lt;BR /&gt;The configuration file looks like this:&lt;/P&gt;
&lt;LI-CODE lang="php"&gt;#  This file was AUTOMATICALLY GENERATED
#  Generated by /bin/dnsmasq_xlate on Tue Jun 18 13:44:47 2024
# 
#  DO NOT EDIT
# 
bind-interfaces
cache-size=1000
no-poll
listen-address=127.0.0.1
server=/#/x.y.z.w
conf-dir=/etc/dnsmasq.d&lt;/LI-CODE&gt;
&lt;P&gt;This tells me the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;It's basically a caching DNS server (x.y.z.w appears to be the DNS server configured in the Gaia OS)&lt;/LI&gt;
&lt;LI&gt;Additional configuration can be bootstrapped from files added in /etc/dnsmasq.d&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether this works/is supported is a separate question.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 19:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220834#M42269</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-15T19:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220836#M42270</link>
      <description>&lt;P&gt;1( What file is that?&lt;/P&gt;
&lt;P&gt;2) should not dnsmasq command give something?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 19:14:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220836#M42270</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-15T19:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220849#M42276</link>
      <description>&lt;P&gt;The configuration file is /etc/dnsmasq.conf&lt;BR /&gt;The error message you receive is because &lt;A href="https://thekelleys.org.uk/dnsmasq/doc.html" target="_self"&gt;dnsmasq&lt;/A&gt; is already running (as stated previously).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 20:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220849#M42276</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-15T20:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220855#M42278</link>
      <description>&lt;P&gt;Never seen or read anything regarding DNS provided by Check Point.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is ns1.checkpoint.com but they deny my DNS request &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;C:\Users\lesle&amp;gt;nslookup therock.com ns1.checkpoint.com&lt;BR /&gt;Server: dns1.zonelabs.com&lt;BR /&gt;Address: 209.87.222.140&lt;/P&gt;
&lt;P&gt;*** dns1.zonelabs.com can't find therock.com: Query refused&lt;/P&gt;
&lt;P&gt;C:\Users\lesle&amp;gt;nslookup ns1.checkpoint.com&lt;BR /&gt;Server: gpon.net&lt;BR /&gt;Address: fe80::1&lt;/P&gt;
&lt;P&gt;Non-authoritative answer:&lt;BR /&gt;Name: ns1.checkpoint.com&lt;BR /&gt;Address: 209.87.222.140&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 20:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220855#M42278</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-15T20:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220864#M42283</link>
      <description>&lt;P&gt;K, gotcha...this is what it looks like in my lab, appears how I set it up.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-EXL-1-s01-01:0]# more dnsmasq.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/dnsmasq_xlate on Fri Jul 12 15:27:11 2024&lt;BR /&gt;#&lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;#&lt;BR /&gt;bind-interfaces&lt;BR /&gt;cache-size=1000&lt;BR /&gt;no-poll&lt;BR /&gt;listen-address=127.0.0.1&lt;BR /&gt;server=/#/8.8.8.8&lt;BR /&gt;server=/#/8.8.4.4&lt;BR /&gt;server=/#/2.2.2.2&lt;BR /&gt;conf-dir=/etc/dnsmasq.d&lt;BR /&gt;[Expert@CP-EXL-1-s01-01:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 21:02:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220864#M42283</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-15T21:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220944#M42300</link>
      <description>&lt;P&gt;John,&lt;/P&gt;
&lt;P&gt;Just wanted to thank you again for providing this. I cant believe how great these dns servers are, its truly amazing. Compared to google DNS, there is literally no comparison...simply outstanding.&lt;/P&gt;
&lt;P&gt;I mean, I even tested it at home and though I have 1.5 GB download abd 1 GB upload fiber through my ISP, when I use quad 9 dns servers, it seems way faster then when uding google DNS.&lt;/P&gt;
&lt;P&gt;Thanks again mate!!! &lt;span class="lia-unicode-emoji" title=":victory_hand:"&gt;✌️&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 12:39:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-question/m-p/220944#M42300</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-16T12:39:38Z</dc:date>
    </item>
  </channel>
</rss>

