<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting the FQDN Domain Object in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-the-FQDN-Domain-Object/m-p/224502#M43137</link>
    <description>&lt;P&gt;Unless your clients are using the exact same DNS servers as as the gateway, this issue is bound to occur.&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk161612&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2024 13:16:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-08-26T13:16:12Z</dc:date>
    <item>
      <title>Troubleshooting the FQDN Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-the-FQDN-Domain-Object/m-p/224444#M43131</link>
      <description>&lt;P&gt;Hello, had a quick issue today.&amp;nbsp; We had traffic failing to match a rule where the destination object used in the rule was a FQDN Domain Object.&lt;/P&gt;&lt;P&gt;The reason for using a Domain Object here is that the destination is an Azure SQL Database using Public Endpoint, where the IP Address will change frequently.&amp;nbsp; By using the Domain Object, we're able to permit the traffic no matter if the Public IP randomly changes or not.&amp;nbsp; This is great, when it works.&lt;/P&gt;&lt;P&gt;When the traffic was not matching, we had to create a single IP Address/Host object to allow it as a work-around.&amp;nbsp; Usually the traffic for this flow hits a different gateway cluster of ours, but due to some failover testing, the traffic was hitting a new gateway cluster.&amp;nbsp; However, on this other cluster, we still have the same rule installed.&lt;/P&gt;&lt;P&gt;Now that the work around was in place I wanted to understand better what went wrong, so after doing some searching I found the command to troubleshoot domain objects is domains_tool (sk161632) and I proceed to log into the security gateway in question and using the domains_tool -d command for the FQDN in the object.&amp;nbsp; The returned output was indeed "Domain is not attached to any IP Address."&lt;/P&gt;&lt;P&gt;I then tried to just ping the FQDN from the gateway, and it resolved to the expected IP address.&amp;nbsp; Now when i ran the domains_tool -d command again right after doing the ping, now it is showing it bound to the expect IP Address?&lt;/P&gt;&lt;P&gt;Not sure if this is a job for TAC, or is any other simple troubleshooting we can do?&amp;nbsp; I did confirm through logs that the domain resolved to 3 different IP Addresses in an hour, so maybe that threw things off a bit?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2024 16:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-the-FQDN-Domain-Object/m-p/224444#M43131</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2024-08-25T16:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting the FQDN Domain Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-the-FQDN-Domain-Object/m-p/224502#M43137</link>
      <description>&lt;P&gt;Unless your clients are using the exact same DNS servers as as the gateway, this issue is bound to occur.&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk161612&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 13:16:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Troubleshooting-the-FQDN-Domain-Object/m-p/224502#M43137</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-26T13:16:12Z</dc:date>
    </item>
  </channel>
</rss>

