<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cluster xl 80.40 - trouble with external dns querys in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/78041#M15891</link>
    <description>&lt;P&gt;Also managed to get this working by enabling the IPS blade (previously had firewall + IA + Mobile access only).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fwaccel conns now shows the inbound and outbound connections with the 'S' flag (PXL enabled).&lt;/P&gt;</description>
    <pubDate>Thu, 12 Mar 2020 03:07:32 GMT</pubDate>
    <dc:creator>chris_denham</dc:creator>
    <dc:date>2020-03-12T03:07:32Z</dc:date>
    <item>
      <title>cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77311#M15734</link>
      <description>&lt;P&gt;Hi i have upgraded a Cluster XL to 80.40&lt;/P&gt;&lt;P&gt;this cluster works only as firewall (NGTP or NGTX isn't active)&lt;/P&gt;&lt;P&gt;in the smartconsole is all green.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dns query from internal to external doesn't work when secure xl is enabled.&lt;/P&gt;&lt;P&gt;if i disable secure xl the dns querys are working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have anyone the same problem?&lt;/P&gt;&lt;P&gt;how can i solve this? (have to wait for a new hotfix?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanx all, regards&lt;/P&gt;&lt;P&gt;flo&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 14:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77311#M15734</guid>
      <dc:creator>Florian_Maier</dc:creator>
      <dc:date>2020-03-05T14:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77578#M15795</link>
      <description>If disabling SecureXL "solves" a problem, it's a bug.&lt;BR /&gt;Open a TAC case, please.</description>
      <pubDate>Sun, 08 Mar 2020 01:18:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77578#M15795</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-08T01:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77629#M15813</link>
      <description>&lt;P&gt;I had the same problem.&amp;nbsp;But there is a solution to bypass the DNS server IP.&amp;nbsp;You can bypass SecureXL (green flow in the picture) as described.&amp;nbsp;This will use the F2F path instead of the acceleration path.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20200308-183104_Edge.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4749iF3310719CFB635D4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20200308-183104_Edge.jpg" alt="Screenshot_20200308-183104_Edge.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How to disable SecureXL for specific IP addresses? Edit the relevant table.def file, define the DNS Server IP addresses, whose traffic should&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;be accelerated&lt;/EM&gt;&lt;SPAN&gt;. Y&lt;/SPAN&gt;&lt;SPAN&gt;ou can find more on this topic in this&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_self" rel="nofollow noopener noreferrer"&gt;sk104468&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;More read here:&lt;BR /&gt;&lt;A title="R80.x - Performance Tuning Tip - Control SecureXL / CoreXL Pathes" href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Control-SecureXL-CoreXL-Pathes/m-p/72006/highlight/true#M14599" target="_self"&gt;&lt;SPAN class="lia-message-read"&gt;- R80.x - Performance Tuning Tip - Control SecureXL / CoreXL Paths&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow" target="_blank" rel="noopener"&gt;- R80.x - Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2020 17:34:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77629#M15813</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-08T17:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77639#M15816</link>
      <description>Obviously that's a workaround, but we should find out why we need to disable SecureXL for this.</description>
      <pubDate>Mon, 09 Mar 2020 00:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/77639#M15816</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-09T00:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/78040#M15890</link>
      <description>&lt;P&gt;Experiencing the same issue after upgrading a Cluster to R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly the DNS traffic goes through 2 x Clusters and the issue goes away after disabling SecureXL on one of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using a bind DNS server, same issue using forwarders or root hints.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like the DNS reply packet is sent twice on the egress interface from the gateway, but is never visible in a tcpdump on the DNS server itself.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 02:07:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/78040#M15890</guid>
      <dc:creator>chris_denham</dc:creator>
      <dc:date>2020-03-12T02:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/78041#M15891</link>
      <description>&lt;P&gt;Also managed to get this working by enabling the IPS blade (previously had firewall + IA + Mobile access only).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fwaccel conns now shows the inbound and outbound connections with the 'S' flag (PXL enabled).&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 03:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/78041#M15891</guid>
      <dc:creator>chris_denham</dc:creator>
      <dc:date>2020-03-12T03:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: cluster xl 80.40 - trouble with external dns querys</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/79830#M16180</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41747"&gt;@chris_denham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;works&lt;/P&gt;&lt;P&gt;but it's only a workaround.&lt;/P&gt;&lt;P&gt;any updates?&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 15:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cluster-xl-80-40-trouble-with-external-dns-querys/m-p/79830#M16180</guid>
      <dc:creator>Florian_Maier</dc:creator>
      <dc:date>2020-03-26T15:57:39Z</dc:date>
    </item>
  </channel>
</rss>

