<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Reputation Cache timer in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/175182#M54936</link>
    <description>&lt;P&gt;Hi, the timer is determined by threadCloud for each url, usually 10-24 hr. It cannot be changed. The ttl in malware_config is not in use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2023 05:26:41 GMT</pubDate>
    <dc:creator>yalmog</dc:creator>
    <dc:date>2023-03-17T05:26:41Z</dc:date>
    <item>
      <title>DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/173731#M54931</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For DNS reputation protections, I'm trying to find how long the cache time is, and where the config file to modify this is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IIRC the AV blade for DNS reputation detects the first attempt, and then blocks all future attempts for queries if it was flagged and cached as bad. this cache I think clears after 12 hours, but i'd like to verify the time on this. My client may want to adjust this to a longer timer before clearing the reputation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 16:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/173731#M54931</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-03-06T16:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/173771#M54932</link>
      <description>&lt;P&gt;IIRC some operations are based on DNS TTL others are based on how full the relevant RAD cache is...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Relevant resources include:&lt;/P&gt;
&lt;P data-unlink="true"&gt;sk92224: Optimizing the categorization of DNS traffic by changing the Resource Classification Mode, for Anti-Virus and Anti-Bot&lt;BR /&gt;sk110214: How to clear DNS cache of HTTP/HTTPS Proxy function without 'cpstop'&lt;BR /&gt;sk89340: Traffic latency might be caused by Anti-Bot / Anti-Virus resource categorization mode set to 'Hold'&lt;BR /&gt;sk74120: Why Anti-Bot and Anti-Virus connections may be allowed even in Prevent mode&lt;BR /&gt;&lt;SPAN&gt;sk92264:&amp;nbsp;ATRG:&amp;nbsp;Anti-Bot&amp;nbsp;and Anti-Virus&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;sk90422: How to modify URL Filtering cache size?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 15:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/173771#M54932</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-08T15:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/173772#M54933</link>
      <description>&lt;P&gt;You could check below file on mgmt server:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$FWDIR/conf/malware_config&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 00:52:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/173772#M54933</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-07T00:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/174044#M54934</link>
      <description>&lt;P&gt;I've reviewed these SKs now, and I'm not finding enough info on the DNS cache within them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from the malware_config file, there is the [dns info] section, which just has a 300TTL and enable variable. I'm wondering if this TTL is 300 minutes/5 hours for the AV cache. Can anyone confirm?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also not seeing anything indicative of changing this within the rad_conf.C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 14:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/174044#M54934</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-03-08T14:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/174074#M54935</link>
      <description>&lt;P&gt;I would assume the TTL is in seconds, which is how the underlying DNS expresses TTL.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 18:15:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/174074#M54935</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-08T18:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/175182#M54936</link>
      <description>&lt;P&gt;Hi, the timer is determined by threadCloud for each url, usually 10-24 hr. It cannot be changed. The ttl in malware_config is not in use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 05:26:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/175182#M54936</guid>
      <dc:creator>yalmog</dc:creator>
      <dc:date>2023-03-17T05:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reputation Cache timer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/206071#M54937</link>
      <description>&lt;P&gt;Is this still the case?&lt;/P&gt;&lt;P&gt;For environments with huge amount of DNS traffic, the cache of 400K might get full and the&amp;nbsp; built-in clearing functions are not sufficient. The next step would be to modify the TTLs so unncessary DNS cache entries does not last as long.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 12:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-Reputation-Cache-timer/m-p/206071#M54937</guid>
      <dc:creator>Albin</dc:creator>
      <dc:date>2024-02-14T12:46:03Z</dc:date>
    </item>
  </channel>
</rss>

