<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using DNS FQDN for object names in policy creation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11313#M99577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team can you please let me know, how to use DNS FQDN for object names in policy creation. What are the advantages and disadvantages and any things I need to take into consideration before deploying them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chandru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Nov 2017 17:25:19 GMT</pubDate>
    <dc:creator>Chandhrasekar_S</dc:creator>
    <dc:date>2017-11-13T17:25:19Z</dc:date>
    <item>
      <title>Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11313#M99577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team can you please let me know, how to use DNS FQDN for object names in policy creation. What are the advantages and disadvantages and any things I need to take into consideration before deploying them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chandru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 17:25:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11313#M99577</guid>
      <dc:creator>Chandhrasekar_S</dc:creator>
      <dc:date>2017-11-13T17:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11314#M99578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In R80.10 there are now two modes: FQDN and non-FQDN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FQDN:&lt;/P&gt;&lt;P&gt;If using FQDN mode (R80.10), the traffic will only match the exact domain.&amp;nbsp; For example:&amp;nbsp; If you defined checkpoint.com, then ONLY checkpoint.com will be matched, traffic that is community.checkpoint.com will &lt;EM&gt;NOT be matched&lt;/EM&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; This is&lt;STRONG&gt; supported in R80.10&lt;/STRONG&gt; and is the &lt;STRONG&gt;default and recommended option.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;non-FQDN:&lt;/P&gt;&lt;P&gt;If FQDN is unchecked, then traffic to the domain and subdomains are matched.&amp;nbsp; So using the example above, if checkpoint.com is defined, then both checkpoint.com and community.checkpoint.com will &lt;EM&gt;be matched&lt;/EM&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS reverse lookup is used if the IP addressed is not cached.&amp;nbsp; So the DNS server will need to support reverse lookup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In R80.10, domain objects do not disable SecureXL templates, so there is support for template acceleration.&amp;nbsp; In previous releases, the order of the rules using domain objects will impact how SecureXL is used.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 18:49:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11314#M99578</guid>
      <dc:creator>grandpafirewall</dc:creator>
      <dc:date>2017-11-13T18:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11315#M99579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There was a long discusstiob about this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This example is not always true "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp; For example:&amp;nbsp; If you defined checkpoint.com, then ONLY checkpoint.com will be matched, traffic that is community.checkpoint.com will&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM style="color: #333333; background-color: #ffffff; border: 0px;"&gt;NOT be matched&lt;/EM&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;." &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;The website might still be hosted under the same ip.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;For example server that host both google.com and checkpoint.com on the same ip. Using fqdn object to allow google.com will also allow checkpoint.com&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 19:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11315#M99579</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2017-11-13T19:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11316#M99580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; I should have clarified that.&amp;nbsp; If community.checkpoint.com and checkpoint.com are &lt;STRONG&gt;not&lt;/STRONG&gt; the same IP address. Thanks for clarifying that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 19:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11316#M99580</guid>
      <dc:creator>grandpafirewall</dc:creator>
      <dc:date>2017-11-13T19:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11317#M99581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks All. Just wondering where should I select the mode - FQDN and non-FQDN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 20:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11317#M99581</guid>
      <dc:creator>Chandhrasekar_S</dc:creator>
      <dc:date>2017-11-13T20:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11318#M99582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TL;DR is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If gateway is lower version than R80.10, you &lt;EM&gt;must&lt;/EM&gt; select non-FQDN.&lt;/LI&gt;&lt;LI&gt;If gateway is R80.10 and above, use FQDN&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 23:06:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11318#M99582</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-13T23:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11319#M99583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use extreme caution when deploying domain objects in your rule base. We added a domain object to our blacklist rule and it took down one of our data centers. Our diamond engineer said:&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;I did some research and asked internally.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;so there is a timeout for Domain Object - it would be related to how long it would take for a DNS request to fail/timeout.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;Which is likely only configure for a couple seconds, but what would cause the slow response as every connection going to this gateway is be queued and going though this and why we eventually were able to connect to the gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;every connection going to the firewall would need to be queued and attempt the dns request before it got proceed to the next rule."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 15px;"&gt;He also said the Check Point recommends that you use domain objects only if &lt;SPAN style="color: #878787; font-weight: 100;"&gt;absolutely&lt;/SPAN&gt; necessary.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2017 17:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11319#M99583</guid>
      <dc:creator>Kirk_Vaughan</dc:creator>
      <dc:date>2017-11-23T17:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11320#M99584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is relevant for non-FQDN Domain Objects and has been the case for a while.&lt;/P&gt;&lt;P&gt;For FQDN, the DNS lookup process should be non-blocking.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2017 19:49:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11320#M99584</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-23T19:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11321#M99585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pre-R80.10, domain objects used only non-FQDN. &amp;nbsp;This basically means if a DNS lookup is required almost every time. &amp;nbsp;A domain defined as checkpoint.com might have a different IP as &lt;A href="http://www.checkpoint.com,"&gt;www.checkpoint.com,&lt;/A&gt;&amp;nbsp;community.checkpoint.com, ftp.checkpoint.com, etc... (Ref: &amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk90401) &amp;nbsp;&lt;/SPAN&gt;The enforcement point is at the mercy of DNS server latency. &amp;nbsp;&amp;nbsp;(I'm summarizing here to get to my point). &amp;nbsp;You are correct in saying to use extreme caution because you need to understand what you are using and the technology behind it.&amp;nbsp; R80.10 implementation is different than previous releases. &amp;nbsp;(Ref: &amp;nbsp;sk41632 and sk120633)&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Nov 2017 06:28:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11321#M99585</guid>
      <dc:creator>grandpafirewall</dc:creator>
      <dc:date>2017-11-24T06:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11322#M99586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone used FQDN objects in a VSX environment on R80.10 ?&amp;nbsp;Trying to determine what ip actually performs the lookup for a VS. Would it be the domain (cma) ip or the chassis ip itself ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2018 11:41:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11322#M99586</guid>
      <dc:creator>Leandro_Nicolet</dc:creator>
      <dc:date>2018-11-12T11:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11323#M99587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to track the current resolution of the FQDN object? For instance an CLI command showing something like:&lt;/P&gt;&lt;P&gt;CNAME, class IN, cname googleapis.l.google.com type A, class IN, addr 172.217.23.10 type A, class IN, addr 216.58.198.234 type A, class IN, addr 216.58.212.74 type A, class IN, addr 216.58.201.42 type A, class IN, addr 216.58.208.138 type A, class IN, addr 216.58.201.10 type A, class IN, addr 216.58.198.170 type A, class IN, addr 216.58.212.106 type A, class IN, addr 216.58.210.42 type A, class IN, addr 216.58.206.74 type A, class IN, addr 216.58.206.138 type A, class IN, addr 216.58.204.42 type A, class IN, addr 216.58.204.74 type A, class IN, addr 172.217.23.42 type A, class IN, addr 216.58.206.106 type A, class IN, addr 216.58.214.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2019 10:16:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11323#M99587</guid>
      <dc:creator>Frederic_Kasmir</dc:creator>
      <dc:date>2019-02-06T10:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11324#M99588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Think such a command is listed here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-3476-domain-objects-fqdn-an-unofficial-atrg" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-3476-domain-objects-fqdn-an-unofficial-atrg&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/11324#M99588</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using DNS FQDN for object names in policy creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/158274#M99589</link>
      <description>&lt;P&gt;What does it mean by &lt;SPAN&gt;(up to 10 levels) described in&amp;nbsp;sk120633 in below sentence? any example to refer for it .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;When FQDN mode is unchecked, traffic to the domain and its sub-domains &lt;EM&gt;&lt;STRONG&gt;(up to 10 levels)&lt;/STRONG&gt;&lt;/EM&gt; is matched on the rule using the non-FQDN Domain object."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 07:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-DNS-FQDN-for-object-names-in-policy-creation/m-p/158274#M99589</guid>
      <dc:creator>Suresh_Shah</dc:creator>
      <dc:date>2022-09-28T07:58:33Z</dc:date>
    </item>
  </channel>
</rss>

