<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS Passive Learning Design Question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77213#M15705</link>
    <description>&lt;P&gt;In regards to the new R80.40 feature, DNS Passive Learning, I'm curious if all DNS requests can be watched or only certain ones.&amp;nbsp; sk161612 talks about using the same resolver as the gateway or configuring a setting in an object to mark it as a DNS server, but in this scenario, the firewall sees the needed DNS requests, just FROM the DNS servers making the recursive request to the internet.&amp;nbsp; It does NOT see the request between the client and the DNS server.&amp;nbsp; I don't know what recursive servers are on the internet, so I can't create objects there. &amp;nbsp;&lt;SPAN&gt;Can the gateway watch the DNS between the DNS server AND the internet?&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-03-04 213858.jpg" style="width: 972px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4689i02EE4B29B83C8757/image-size/large?v=v2&amp;amp;px=999" role="button" title="Annotation 2020-03-04 213858.jpg" alt="Annotation 2020-03-04 213858.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2020 03:46:42 GMT</pubDate>
    <dc:creator>Brian_Deutmeyer</dc:creator>
    <dc:date>2020-03-05T03:46:42Z</dc:date>
    <item>
      <title>DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77213#M15705</link>
      <description>&lt;P&gt;In regards to the new R80.40 feature, DNS Passive Learning, I'm curious if all DNS requests can be watched or only certain ones.&amp;nbsp; sk161612 talks about using the same resolver as the gateway or configuring a setting in an object to mark it as a DNS server, but in this scenario, the firewall sees the needed DNS requests, just FROM the DNS servers making the recursive request to the internet.&amp;nbsp; It does NOT see the request between the client and the DNS server.&amp;nbsp; I don't know what recursive servers are on the internet, so I can't create objects there. &amp;nbsp;&lt;SPAN&gt;Can the gateway watch the DNS between the DNS server AND the internet?&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-03-04 213858.jpg" style="width: 972px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4689i02EE4B29B83C8757/image-size/large?v=v2&amp;amp;px=999" role="button" title="Annotation 2020-03-04 213858.jpg" alt="Annotation 2020-03-04 213858.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 03:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77213#M15705</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2020-03-05T03:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77581#M15797</link>
      <description>Only the requests to known DNS servers can be watched.&lt;BR /&gt;The reason for this is that DNS requests could traverse the gateway that are going to malicious DNS servers.&lt;BR /&gt;We assume the gateway is using a "trusted" DNS server.&lt;BR /&gt;Any other DNS server defined as described in sk161612 is considered trusted.&lt;BR /&gt;FYI, the list and IPs of the root name servers is well known and published: &lt;A href="https://www.iana.org/domains/root/servers" target="_blank"&gt;https://www.iana.org/domains/root/servers&lt;/A&gt;&lt;BR /&gt;What your internal DNS server is using is a different matter, and I assume whoever manages your DNS server can tell you that.</description>
      <pubDate>Sun, 08 Mar 2020 03:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77581#M15797</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-08T03:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77585#M15798</link>
      <description>&lt;P&gt;What about requests FROM known DNS servers?&amp;nbsp; Can those be watched?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 06:00:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77585#M15798</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2020-03-08T06:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77628#M15812</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5785"&gt;@Brian_Deutmeyer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;DNS Passive Learning is a mechanism for constructing an IP / domain cache in which DNS traffic will be inspected and parsed for these purposes.&amp;nbsp;This only works for defined DNS servers in an FW object.&amp;nbsp;In this case the DNS answers are written to the FW DNS cache.&amp;nbsp;It does not work for undefined DNS servers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;DNS Passive Learning is enabled by default in R80.40.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 17:17:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77628#M15812</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-08T17:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77637#M15815</link>
      <description>No, the mechanism will only trust DNS information received from known DNS servers, regardless of who is making the query (a client or a DNS server).</description>
      <pubDate>Mon, 09 Mar 2020 00:08:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/77637#M15815</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-09T00:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/89098#M17885</link>
      <description>Forgive me for asking, but what exactly is DNS Passive Learning from Checkpoint? I've been trying to do some searches both on the forums here, the Checkpoint KB's and the Internet as a whole and I'm getting glimpses of what it's supposed to do, but nothing is completely clear about what it provides? All of my DNS servers are marked as DNS servers on my firewalls as described, so I presume my gateways are using this DNS Passive Learning, but I don't know exactly what that means?</description>
      <pubDate>Thu, 18 Jun 2020 21:20:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/89098#M17885</guid>
      <dc:creator>Rob_Bush</dc:creator>
      <dc:date>2020-06-18T21:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/89100#M17886</link>
      <description>&lt;P&gt;Disclaimer: I don't have this setup as I'm waiting for an additional feature.&lt;/P&gt;&lt;P&gt;Check out&amp;nbsp;&lt;A title="sk161612" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk161612" target="_blank" rel="noopener"&gt;&lt;FONT&gt;sk161612&lt;/FONT&gt; &lt;/A&gt;for more information.&lt;/P&gt;&lt;P&gt;This feature allows you to specify a domain (and the subdomains) to allow access to.&amp;nbsp; Let's say a source needs access to *.something.biz and there isn't' a relevant application.&amp;nbsp; You can try to write you own application, but often, that might not be feasible (think non-web encrypted traffic). &amp;nbsp; The gateway can watch the DNS requests looking for anything that matches something.biz and store the corresponding IPs in its cache.&amp;nbsp; This way when the rule in question is evaluated, the gateway can check the cache and allow/deny access. &amp;nbsp;&lt;/P&gt;&lt;P&gt;A domain object won't work here because reverse DNS doesn't exist or doesn't match the site.&lt;/P&gt;&lt;P&gt;An FQDN domain object won't work here because you don't know all the FQDNs that will be called.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sense?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 21:51:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/89100#M17886</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2020-06-18T21:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/89102#M17887</link>
      <description>But, for this feature to work, queries to those trusted DNS servers must traverse the gateway.&lt;BR /&gt;Otherwise, we can't "learn" about these mappings passively.</description>
      <pubDate>Thu, 18 Jun 2020 21:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/89102#M17887</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-18T21:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/95573#M18818</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have two questions regarding DNS passive learning:&lt;/P&gt;&lt;P&gt;1) will the DNS-entries, which are learned by DNS passive learning, be replicatet to the standby-member in an Cluster-environment (active/passive)&lt;/P&gt;&lt;P&gt;2) how can I querry the list which is learned by DNS passive learning. Can it be done with the "domains_tool"?&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;</description>
      <pubDate>Sat, 29 Aug 2020 12:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/95573#M18818</guid>
      <dc:creator>shasenst</dc:creator>
      <dc:date>2020-08-29T12:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/107244#M20529</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/49985"&gt;@shasenst&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I'm not 100% sure, but checking it out on a cluster, I see some entries replicated for a domain, but not all.&amp;nbsp; So I'm not sure if there is a time period before a sync or what.&lt;/P&gt;&lt;P&gt;2. domains_tool -d &amp;lt;domain&amp;gt; || domains_tool -ip &amp;lt;ip_addr&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more side note on something I discovered.&amp;nbsp; If you are watching the recursive traffic from a local DNS server to the authoritative name server and the request type is CNAME (not A), the firewall will not populate the entry since the response isn't an IP address and passive learning doesn't watch the chain.&amp;nbsp; If the firewall is watching client to DNS server communications, this is NOT an issue since the DNS server will respond with the full chain (CNAME + A).&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 18:57:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/107244#M20529</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2021-01-07T18:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/198687#M33216</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;/P&gt;
&lt;P&gt;it's been a while ( Since R55 ) lol&lt;/P&gt;
&lt;P&gt;Can you clarify , but i believe so , if the customer has an internal DNS server behind the GW that is authoritative , so no forwarding nor relay to an external specific DNS server ( SP DNS for instance ) , it will not work right ?&lt;/P&gt;
&lt;P&gt;as we need to declare the external DNS server to which requests will be monitored ...&lt;/P&gt;
&lt;P&gt;i assume we need to declare a non-FQDN domain object as well , right ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Farid&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 16:09:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/198687#M33216</guid>
      <dc:creator>faridb</dc:creator>
      <dc:date>2023-11-22T16:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/198777#M33226</link>
      <description>&lt;P&gt;For DNS Passive Learning to work, the Security Gateway must be in the path to actually see the DNS Requests and the “trusted” DNS servers must be explicitly configured (either using the same DNS as configured in on the gateway OR explicitly configured DNS Server objects).&lt;BR /&gt;In the environment you’ve described, additional configuration will be required to make this work.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 14:40:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/198777#M33226</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-23T14:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/198790#M33230</link>
      <description>&lt;P&gt;thank you , i understand ...and this needs to be clarified with the customer for my particular use case.&lt;/P&gt;
&lt;P&gt;can you confirm that it will enhance the situation where non-fqdn domain are used and&amp;nbsp; in the case where no reverse dns entries exists in DNS ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 16:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/198790#M33230</guid>
      <dc:creator>faridb</dc:creator>
      <dc:date>2023-11-23T16:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Passive Learning Design Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/199202#M33267</link>
      <description>&lt;P&gt;Not sure if this will work with non-FQDN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 22:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Passive-Learning-Design-Question/m-p/199202#M33267</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-28T22:42:56Z</dc:date>
    </item>
  </channel>
</rss>

