<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VSX Clustering R80.20 DNS resolving error msg in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65776#M9529</link>
    <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;I am seeing constant Alert error messages in our logs with reason: Firewall - Domain resolving error. Check DNS configuration on the gateway (0) .&lt;/P&gt;&lt;P&gt;Here are the statistics: R80.20, running on VSX, JHF Take 103 applied,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially I thought the issue was being caused by the fact that in VSX the DNS servers for each context are the same (SK152873 - a large oversight if you ask me but) so with some redesign I was able to find 3 common DNS targets that would work in this scenario. Once that was applied, I still am seeing tons of these alert errors.&lt;/P&gt;&lt;P&gt;From the CLI I am able to confirm that all of the VSX contexts resolve DNS using dig/nslookup etc so I am not sure why I would be seeing this behavior&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 24 Oct 2019 13:38:10 GMT</pubDate>
    <dc:creator>jbfixurpc_cew</dc:creator>
    <dc:date>2019-10-24T13:38:10Z</dc:date>
    <item>
      <title>VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65776#M9529</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;I am seeing constant Alert error messages in our logs with reason: Firewall - Domain resolving error. Check DNS configuration on the gateway (0) .&lt;/P&gt;&lt;P&gt;Here are the statistics: R80.20, running on VSX, JHF Take 103 applied,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially I thought the issue was being caused by the fact that in VSX the DNS servers for each context are the same (SK152873 - a large oversight if you ask me but) so with some redesign I was able to find 3 common DNS targets that would work in this scenario. Once that was applied, I still am seeing tons of these alert errors.&lt;/P&gt;&lt;P&gt;From the CLI I am able to confirm that all of the VSX contexts resolve DNS using dig/nslookup etc so I am not sure why I would be seeing this behavior&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Oct 2019 13:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65776#M9529</guid>
      <dc:creator>jbfixurpc_cew</dc:creator>
      <dc:date>2019-10-24T13:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65806#M9530</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess you are using domain objects, right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 16:35:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65806#M9530</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2019-10-24T16:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65810#M9531</link>
      <description>As a matter of fact, yes, were trying to do that. What I am failing to understand is that from an external resource I can generate DNS traffic to a DNS server behind the cluster, and I see the error appear in that manor, sometimes... It's completely hit or miss which is confusing to say the least, sometimes I see the hits with no alerts, other times with the alert "Firewall - Domain resolving error. Check DNS configuration on the gateway (0)" which makes no sense to ,e.</description>
      <pubDate>Thu, 24 Oct 2019 16:41:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65810#M9531</guid>
      <dc:creator>jbfixurpc_cew</dc:creator>
      <dc:date>2019-10-24T16:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65844#M9532</link>
      <description>&lt;P&gt;We had such issue in the past which should be solved.&lt;/P&gt;
&lt;P&gt;I will check it internaly and will update.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 18:34:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65844#M9532</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2019-10-24T18:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65992#M9533</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the fix included in on going JHF take 117, if you can move to this take it will be great.&lt;/P&gt;
&lt;P&gt;if not i suggest to open a ticket for CP support to ask a port fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ilya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2019 10:13:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/65992#M9533</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2019-10-27T10:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/72302#M9534</link>
      <description>&lt;P&gt;Hi Ilya,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have same issue on r80.30 HF take 111, can you check internaly if that fix was ported to r80.30 ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 10:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/72302#M9534</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-01-15T10:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/72303#M9535</link>
      <description>&lt;P&gt;Hi Khalid,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fix already included in R80.30 GA version so i suggest to open a TAC case and share it with me so i can check with RnD owners.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 11:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/72303#M9535</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-01-15T11:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Clustering R80.20 DNS resolving error msg</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/73359#M9536</link>
      <description>&lt;P&gt;Probably you have resolved it by now but if not make sure that TCP DNS lookups are allowed from your gateway&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Domain-Objects-FQDN-An-Unofficial-ATRG/m-p/72958#M10845" target="_blank"&gt;https://community.checkpoint.com/t5/General-Management-Topics/Domain-Objects-FQDN-An-Unofficial-ATRG/m-p/72958#M10845&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2020 12:55:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Clustering-R80-20-DNS-resolving-error-msg/m-p/73359#M9536</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-01-25T12:55:23Z</dc:date>
    </item>
  </channel>
</rss>

