<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Publishing a service with multiple DNS records associated with a Single Públic IP using Check Point in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67899#M13880</link>
    <description>&lt;P&gt;Dear Mates&lt;/P&gt;&lt;P&gt;We wish to migrate one of our critical services from TMG to Check point. Most of the services have already been migrated except this one last service.&lt;/P&gt;&lt;P&gt;Currently, the service has 4 DNS records associated with a single Public IP, the public IP is then NATed internally to a private IP of the TMG Proxy. Taking into account that this service runs on three machines which where put into a pool of a single DNS record internally.&lt;/P&gt;&lt;P&gt;So the Proxy has a rule like:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source: Any&lt;/P&gt;&lt;P&gt;Destination: DNS record (A single DNS record where all the machines where added)&lt;/P&gt;&lt;P&gt;Service: http, https&lt;/P&gt;&lt;P&gt;Action: Accept&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we translate this configuration in Check Point?&lt;/P&gt;&lt;P&gt;We are using R80.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2019 12:33:45 GMT</pubDate>
    <dc:creator>Di_Junior</dc:creator>
    <dc:date>2019-11-20T12:33:45Z</dc:date>
    <item>
      <title>Publishing a service with multiple DNS records associated with a Single Públic IP using Check Point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67899#M13880</link>
      <description>&lt;P&gt;Dear Mates&lt;/P&gt;&lt;P&gt;We wish to migrate one of our critical services from TMG to Check point. Most of the services have already been migrated except this one last service.&lt;/P&gt;&lt;P&gt;Currently, the service has 4 DNS records associated with a single Public IP, the public IP is then NATed internally to a private IP of the TMG Proxy. Taking into account that this service runs on three machines which where put into a pool of a single DNS record internally.&lt;/P&gt;&lt;P&gt;So the Proxy has a rule like:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source: Any&lt;/P&gt;&lt;P&gt;Destination: DNS record (A single DNS record where all the machines where added)&lt;/P&gt;&lt;P&gt;Service: http, https&lt;/P&gt;&lt;P&gt;Action: Accept&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we translate this configuration in Check Point?&lt;/P&gt;&lt;P&gt;We are using R80.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 12:33:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67899#M13880</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-11-20T12:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67905#M13881</link>
      <description>So you are using DNS to run round robin load sharing on the webservers.&lt;BR /&gt;I don't think this will even work with the use of dynamic objects, as when it is resolved (ie to a internal DNS server with multiple entries), it will cache the result for a certain time, instead of asking for the same DNS entry again for every request.&lt;BR /&gt;Next to that this is really a job for a load-balancer.</description>
      <pubDate>Wed, 20 Nov 2019 12:58:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67905#M13881</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-11-20T12:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67934#M13889</link>
      <description>Hi Maarten&lt;BR /&gt;&lt;BR /&gt;Thanks for your feedback.&lt;BR /&gt;&lt;BR /&gt;I have been reading about Logical Server objects, and it seems interesting.&lt;BR /&gt;&lt;BR /&gt;I just have a question, in my situation since the service runs on three machines with internal IPs, and accessible through a single public Ip, I would like to know if its possible to have a network group with the three machines with internal IP, and create e logical server object with the Public Ip? Or the logical server must be in the same subnet of the internal machines.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Nov 2019 17:42:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/67934#M13889</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-11-20T17:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/68173#M13936</link>
      <description>Take a look at this old explanation from R76 - I guess it is still valid as the logical server objects seem to be very old and kinda legacy (like for example "service with resource objects").&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R76/CP_R76_SGW_WebAdmin/6662.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R76/CP_R76_SGW_WebAdmin/6662.htm&lt;/A&gt;</description>
      <pubDate>Fri, 22 Nov 2019 21:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/68173#M13936</guid>
      <dc:creator>Maik</dc:creator>
      <dc:date>2019-11-22T21:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/68210#M13945</link>
      <description>&lt;P&gt;Di_Junior,&lt;/P&gt;&lt;P&gt;logical server or „connect control“ is your solution.&lt;/P&gt;&lt;P&gt;This is Check Points solution for LoadBalancing of incoming connections and is still supported on R80.30.&lt;/P&gt;&lt;P&gt;You need one external IP and forward them to more then one internal server. The distribution is possible via round robin, failover and some other options.&lt;/P&gt;&lt;P&gt;Please be aware that you can only define this for IP-addresses not for FQDNs. But as you wrote you have more then one FQDN pointing all to one IP. Alle requests to this IP are then forward as define in your distribution configuration.&lt;/P&gt;&lt;P&gt;If you want FQDN-A forwarded to internal-IP-A and FQDN-B forwarded to internal-IP-B then connect control is not your solution !&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2019 18:45:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/68210#M13945</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-11-23T18:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/68394#M13956</link>
      <description>Thanks everyone, it seems that Logical Sever will achieve my purpose. I will update you when I am done with the implementation.&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Mon, 25 Nov 2019 13:58:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/68394#M13956</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-11-25T13:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/186350#M31103</link>
      <description>&lt;P&gt;Hi dear Wolfgan,&lt;/P&gt;&lt;P&gt;Can you provide information regarding FQDN forwarding. I am facing this problem and cannot find information. How it should be configured in checkpoint?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 12:02:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/186350#M31103</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-07-13T12:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing a service with multiple DNS records associated with a Single Públic IP using Check Po</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/186370#M31115</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/96959"&gt;@nemezis_rock&lt;/a&gt;&amp;nbsp;FQDN forwarding can be done with Reverse Proxy feature of the MobileAccessBlade. Be aware there is no GUI to configure this, everything is done via console.&lt;/P&gt;
&lt;P&gt;&lt;A title="Mobile Access Reverse Proxy" href="https://support.checkpoint.com/results/sk/sk110348" target="_blank" rel="noopener"&gt;Mobile Access Reverse Proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title="Mobile Access R81.10 Administration Guide - Reverse Proxy" href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_MobileAccess_AdminGuide/Topics-MABG/Reverse-Proxy.htm" target="_blank" rel="noopener"&gt;Mobile Access R81.10 Administration Guide - Reverse Proxy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 14:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-a-service-with-multiple-DNS-records-associated-with-a/m-p/186370#M31115</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-07-13T14:02:53Z</dc:date>
    </item>
  </channel>
</rss>

