<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Amount of FQDN Domains in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245274#M47763</link>
    <description>&lt;P&gt;In what capacity are you using FQDN Domains?&lt;BR /&gt;There's a couple different limits involved here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How FDQN Objects are resolved:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk90401" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk90401&lt;/A&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;There is a limit in the number of entries in the relevant tables&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Number of objects supported:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Maximum-Supported-Items.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Maximum-Supported-Items.htm&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Number of Network Feed objects (R81.20+, believe it is 500).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Depending on your exact use case, there may be ways to mitigate these limits.&lt;/P&gt;</description>
    <pubDate>Mon, 31 Mar 2025 17:39:03 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-03-31T17:39:03Z</dc:date>
    <item>
      <title>Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245272#M47762</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I would like to know how many domains a Gateway supports, with more than 5,000 FQDN domains?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 17:15:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245272#M47762</guid>
      <dc:creator>smorales31</dc:creator>
      <dc:date>2025-03-31T17:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245274#M47763</link>
      <description>&lt;P&gt;In what capacity are you using FQDN Domains?&lt;BR /&gt;There's a couple different limits involved here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How FDQN Objects are resolved:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk90401" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk90401&lt;/A&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;There is a limit in the number of entries in the relevant tables&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Number of objects supported:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Maximum-Supported-Items.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Maximum-Supported-Items.htm&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Number of Network Feed objects (R81.20+, believe it is 500).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Depending on your exact use case, there may be ways to mitigate these limits.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 17:39:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245274#M47763</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-31T17:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245275#M47764</link>
      <description>&lt;P&gt;Let us know if you find the official answer. Below is what AI shows : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;DIV class="WaaZC"&gt;
&lt;DIV class="RJPOee EIJn2"&gt;
&lt;DIV class="rPeykc" data-hveid="CAIQAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQo_EKegQIAhAB"&gt;&lt;SPAN data-huuid="5061905941076910082"&gt;In Check Point,&amp;nbsp;&lt;MARK class="QVRyCf"&gt;you can define FQDN objects to match traffic to specific domains, with a limit of 100 FQDN objects and 1000 domains per account, and each FQDN object can contain a maximum of 1000 domains&lt;/MARK&gt;.&lt;SPAN class="pjBG2e" data-cid="d6f66615-3a1d-494c-bb3d-a2bf4919fade"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="NPrrbc" data-cid="d6f66615-3a1d-494c-bb3d-a2bf4919fade" data-uuids="5061905941076910082"&gt;
&lt;DIV class="BMebGe btku5b fCrZyc LwdV0e FR7ZSc OJeuxf" tabindex="0" role="button" aria-label="View related links" data-hveid="CAYQAg" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQ3fYKegQIBhAC"&gt;
&lt;DIV class="niO4u"&gt;
&lt;DIV class="kHtcsd"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="WaaZC"&gt;
&lt;DIV class="RJPOee EIJn2"&gt;
&lt;DIV class="rPeykc uP58nb" data-hveid="CAQQAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQo_EKegQIBBAB"&gt;&lt;SPAN data-huuid="5061905941076910548"&gt;&lt;SPAN aria-level="2"&gt;Here's a more detailed breakdown:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="WaaZC"&gt;
&lt;DIV class="RJPOee EIJn2"&gt;
&lt;UL data-hveid="CD4QAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQm_YKegQIPhAB"&gt;
&lt;LI class="K3KsMc"&gt;
&lt;DIV class="zMgcWd dSKvsb" data-il=""&gt;
&lt;DIV data-crb-p=""&gt;
&lt;DIV class="xFTqob"&gt;
&lt;DIV class="Gur8Ad"&gt;&lt;SPAN data-huuid="5061905941076913295"&gt;&lt;STRONG&gt;FQDN Object Limits:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="vM0jzc"&gt;
&lt;UL data-hveid="CB8QAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQm_YKegQIHxAB"&gt;
&lt;LI&gt;&lt;SPAN data-huuid="5061905941076911946"&gt;A firewall supports a total of 100 FQDN objects.&lt;SPAN class="pjBG2e" data-cid="2770d43a-08ad-4565-93ae-31fd8a4230f0"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="NPrrbc" data-cid="2770d43a-08ad-4565-93ae-31fd8a4230f0" data-uuids="5061905941076911946"&gt;
&lt;DIV class="BMebGe btku5b fCrZyc LwdV0e FR7ZSc OJeuxf" tabindex="0" role="button" aria-label="View related links" data-hveid="CA4QAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQ3fYKegQIDhAB"&gt;
&lt;DIV class="niO4u"&gt;
&lt;DIV class="kHtcsd"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-huuid="5061905941076912412"&gt;FQDN objects can contain a maximum of 1000 domains per account.&lt;SPAN class="pjBG2e" data-cid="64229e6c-f904-4571-b831-ca64a6d649a6"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="NPrrbc" data-cid="64229e6c-f904-4571-b831-ca64a6d649a6" data-uuids="5061905941076912412"&gt;
&lt;DIV class="BMebGe btku5b fCrZyc LwdV0e FR7ZSc OJeuxf" tabindex="0" role="button" aria-label="View related links" data-hveid="CBYQAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQ3fYKegQIFhAB"&gt;
&lt;DIV class="niO4u"&gt;
&lt;DIV class="kHtcsd"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="K3KsMc"&gt;
&lt;DIV class="zMgcWd dSKvsb" data-il=""&gt;
&lt;DIV data-crb-p=""&gt;
&lt;DIV class="xFTqob"&gt;
&lt;DIV class="Gur8Ad"&gt;&lt;SPAN data-huuid="5061905941076912878"&gt;&lt;STRONG&gt;Examples of FQDN Object Usage:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="vM0jzc"&gt;
&lt;UL data-hveid="CC8QAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQm_YKegQILxAB"&gt;
&lt;LI&gt;&lt;SPAN data-huuid="5061905941076911529"&gt;One FQDN object per rule, across 100 rules.&lt;SPAN class="pjBG2e" data-cid="6f61908d-fc65-4640-ad05-8625397549fc"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="NPrrbc" data-cid="6f61908d-fc65-4640-ad05-8625397549fc" data-uuids="5061905941076911529"&gt;
&lt;DIV class="BMebGe btku5b fCrZyc LwdV0e FR7ZSc OJeuxf" tabindex="0" role="button" aria-label="View related links" data-hveid="CBQQAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQ3fYKegQIFBAB"&gt;
&lt;DIV class="niO4u"&gt;
&lt;DIV class="kHtcsd"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-huuid="5061905941076911995"&gt;100 FQDN objects contained in a single rule.&lt;SPAN class="pjBG2e" data-cid="3c09d447-99f5-4728-b3db-b9e4f382c6f0"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="NPrrbc" data-cid="3c09d447-99f5-4728-b3db-b9e4f382c6f0" data-uuids="5061905941076911995"&gt;
&lt;DIV class="BMebGe btku5b fCrZyc LwdV0e FR7ZSc OJeuxf" tabindex="0" role="button" aria-label="View related links" data-hveid="CB4QAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQ3fYKegQIHhAB"&gt;
&lt;DIV class="niO4u"&gt;
&lt;DIV class="kHtcsd"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-huuid="5061905941076912461"&gt;Ten FQDN objects containing 100 domains each.&lt;SPAN class="pjBG2e" data-cid="d96ca230-e12b-4754-81bf-a7779c7a29f0"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="NPrrbc" data-cid="d96ca230-e12b-4754-81bf-a7779c7a29f0" data-uuids="5061905941076912461"&gt;
&lt;DIV class="BMebGe btku5b fCrZyc LwdV0e FR7ZSc OJeuxf" tabindex="0" role="button" aria-label="View related links" data-hveid="CCMQAQ" data-ved="2ahUKEwiNkfne77SMAxUDnokEHTRKEMcQ3fYKegQIIxAB"&gt;
&lt;DIV class="niO4u"&gt;
&lt;DIV class="kHtcsd"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-huuid="5061905941076912927"&gt;100 FQDN objects containing ten domains each.&lt;SPAN class="pjBG2e" data-cid="2b4ba228-a91c-4432-ba2b-c8cfa07b2d76"&gt;&lt;SPAN class="UV3uM"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 Mar 2025 17:46:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245275#M47764</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-31T17:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245296#M47772</link>
      <description>&lt;P&gt;Understanding that the network objects in each domain are 100,000,&lt;/P&gt;&lt;P&gt;There is no defined limit for domain objects, correct?&lt;/P&gt;&lt;P&gt;Could there be 100,000 domain objects?&lt;/P&gt;&lt;P&gt;Knowing that it may affect performance.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 20:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245296#M47772</guid>
      <dc:creator>smorales31</dc:creator>
      <dc:date>2025-03-31T20:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245297#M47773</link>
      <description>&lt;P&gt;Considering:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The default table sizes for the various domain objects tops out at 25,000&lt;/LI&gt;
&lt;LI&gt;The gateway tries to resolve the IPs for FQDNs every second&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I suspect you will have serious issues with that many domains.&lt;BR /&gt;Which raises the question of what the actual use case is here.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 20:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245297#M47773</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-31T20:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245492#M47822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P class=""&gt;So, can 100 FQDN objects and 1000 domains be created per object?&lt;/P&gt;&lt;P class=""&gt;What I don't understand is if an FQDN object can only have one domain added, for example, .eltiempo.com. So where are more domains added?&lt;/P&gt;&lt;P class=""&gt;I'm not quite understanding&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 14:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245492#M47822</guid>
      <dc:creator>smorales31</dc:creator>
      <dc:date>2025-04-02T14:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245509#M47836</link>
      <description>&lt;P&gt;Not sure what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;promoted the AI with, but that answer is flat out wrong as a&amp;nbsp;domain object can only hold a SINGLE FQDN.&lt;BR /&gt;There are multiple type of objects that can be used depending on the exact use case and capabilities are.&lt;BR /&gt;I suggest you have a look at a session I recently did on web filtering that might help your understanding:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Web-Filtering-Best-Practices-March-2025-Video-and-Slides/m-p/244980#M47695" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Web-Filtering-Best-Practices-March-2025-Video-and-Slides/m-p/244980#M47695&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Most likely, you'll probably want to use a Network Feed object to define that many FQDNs (available in R81.20 and above).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 19:12:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245509#M47836</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-02T19:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Amount of FQDN Domains</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245512#M47838</link>
      <description>&lt;P&gt;I actually looked that over myself as well and does not make much sense, agree. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;advised, network feeds might be a good idea.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 19:21:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Amount-of-FQDN-Domains/m-p/245512#M47838</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-02T19:21:22Z</dc:date>
    </item>
  </channel>
</rss>

