<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN: Domain vs Application in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89606#M79644</link>
    <description>The method we use is quite simple:&lt;BR /&gt;You create a Custom Category called Whitelist and one called Blacklist&lt;BR /&gt;You add a rule to the Application control policy that will allow traffic to the Whitelist category. and above it you add a rule that blocks the Blacklist category.,&lt;BR /&gt;Now when you need to add a custom Application/Site to the whitelist or blacklist, while creating it you just set the Category to the desired Whitelist or Bracklist. &lt;BR /&gt;Now when you push policy the newly added site is already added to the list and will be allowed/blocked accordingly.</description>
    <pubDate>Tue, 23 Jun 2020 20:48:05 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2020-06-23T20:48:05Z</dc:date>
    <item>
      <title>FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89483#M79640</link>
      <description>&lt;P&gt;Little Background: I am Sys admin with a little Networking background. with a very junior network guy that I am helping with probably less experience than me on this topic&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inherited a client with smart console r80.20...&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have reviewed many of the suggestion on Domain Vs Application... I am missing something and in despreate need to get this functionality working as I need suse updates, azure backups, and SQL backups for my VM's.&lt;/P&gt;&lt;P&gt;I simply need to add *.opensuse.org, so I can get to&amp;nbsp; a.opensuse.org, b.opensuse.org, c,opensuse.org&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've added a domain rule for&amp;nbsp;.opensuse.org with FQDN unchecked - I tried both.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still not able to telnet to any of the services or anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I suppose to do to get all the subdomains added?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you very much in advance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 21:33:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89483#M79640</guid>
      <dc:creator>britt1kj</dc:creator>
      <dc:date>2020-06-22T21:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89485#M79641</link>
      <description>There are two types of objects that are relevant here: FDQN Domain Objects and Custom Application/Site.&lt;BR /&gt;For a detailed discussion about this: &lt;A href="https://community.checkpoint.com/t5/General-Topics/Domain-objects-FQDN-mode-vs-Custom-Applications-Sites/m-p/84543" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Domain-objects-FQDN-mode-vs-Custom-Applications-Sites/m-p/84543&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;While we support domain objects that allow *.somedomain.com, it relies on Reverse DNS (rarely works) and disables SecureXL templates (decreased performance).&lt;BR /&gt;In R80.40, assuming the DNS queries always go through the gateway, mappings can be learned passively by observing the DNS queries to the trusted DNS server.&lt;BR /&gt;That resolves the "Reverse DNS" problem with Domain Objects but not the performance issue, as far as I know. &lt;BR /&gt;See: &lt;A href="https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77213#M15705" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77213#M15705&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;All of this boils down to the following:&lt;BR /&gt;1. If the traffic is HTTP/HTTPS, you can use Custom Application/Sites.&lt;BR /&gt;2. If the traffic is anything else, Domain Objects should be used. Unless you are using R80.40 and DNS queries go through the gateway to a trusted DNS server, you will have to create an object for each FQDN to allow.</description>
      <pubDate>Mon, 22 Jun 2020 21:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89485#M79641</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-22T21:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89570#M79642</link>
      <description>&lt;P&gt;Okay, sounds good... Is there a guide to whitelisting through&amp;nbsp;&lt;SPAN&gt;Custom Application/Sites&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I can see where to create but can't figure out where it applies to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 15:59:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89570#M79642</guid>
      <dc:creator>britt1kj</dc:creator>
      <dc:date>2020-06-23T15:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89579#M79643</link>
      <description>It comes down to having an explicit rule in your Access Policy that allows the desired traffic.&lt;BR /&gt;In the case of a Custom Application/Site, it means having a rule that uses the object you created as the Service/Application (note that it only applies to Web traffic).&lt;BR /&gt;In the case of a Domain Object, it means having a rule that uses the Domain Object as the destination and the relevant services listed in the rule.</description>
      <pubDate>Tue, 23 Jun 2020 16:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89579#M79643</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-23T16:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89606#M79644</link>
      <description>The method we use is quite simple:&lt;BR /&gt;You create a Custom Category called Whitelist and one called Blacklist&lt;BR /&gt;You add a rule to the Application control policy that will allow traffic to the Whitelist category. and above it you add a rule that blocks the Blacklist category.,&lt;BR /&gt;Now when you need to add a custom Application/Site to the whitelist or blacklist, while creating it you just set the Category to the desired Whitelist or Bracklist. &lt;BR /&gt;Now when you push policy the newly added site is already added to the list and will be allowed/blocked accordingly.</description>
      <pubDate>Tue, 23 Jun 2020 20:48:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89606#M79644</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-06-23T20:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89699#M79645</link>
      <description>&lt;P&gt;Thanks for the Reply!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a simple Domain base rule section with an action Accept... I've published many times but no matter what I've I cannot telnet to any other sites.&amp;nbsp; Its getting blocked on our catch rules...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Very new with this appliance,&amp;nbsp; I appreciate your patience and understanding.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 14:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89699#M79645</guid>
      <dc:creator>britt1kj</dc:creator>
      <dc:date>2020-06-24T14:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN: Domain vs Application</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89700#M79646</link>
      <description>Publish does not install the policy on your gateway!!&lt;BR /&gt;You need to click the Install Policy button, top left or when looking at the policy in the top in the middle.</description>
      <pubDate>Wed, 24 Jun 2020 14:49:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FQDN-Domain-vs-Application/m-p/89700#M79646</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-06-24T14:49:26Z</dc:date>
    </item>
  </channel>
</rss>

