<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81301#M16422</link>
    <description>&lt;P&gt;Hey Daemon, I should have asked you this one 20 years ago. &amp;nbsp;I kept meaning to test it to see how it operated, but it was never important enough to spend the time on.... I mean, who actually USES domain objects? &amp;nbsp;I have some follow up questions for clarity if I may...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When did the FQDN checkbox appear? &amp;nbsp;Was it always there?&lt;/LI&gt;&lt;LI&gt;I thought the prefixed "." differentiated whether it was a forward or reverse lookup... is this true?&lt;/LI&gt;&lt;LI&gt;Did it ALWAYS have both forward and reverse options?&lt;/LI&gt;&lt;LI&gt;With reverse lookup, when does the lookup take place? What process does it? &amp;nbsp;While the lookup is happening, is it a default match, no match, or are connections held?&lt;/LI&gt;&lt;LI&gt;Finally, any insight on why the third option is not provided that some other firewalls offer, which is to cache relevant forward lookups that the firewalls sees passing through and use them to inform a list of possible IP addresses?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks! Hope you're well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2020 10:45:22 GMT</pubDate>
    <dc:creator>Greg_Harewood</dc:creator>
    <dc:date>2020-04-08T10:45:22Z</dc:date>
    <item>
      <title>The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80222#M16245</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, engineers, I would like to know the workflow difference between creating domain and Custom Applications/Sites to create urls&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12345.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5235i72B6179A1A8D58F5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="12345.png" alt="12345.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="123456.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5236iD4D112CFA1FBB9FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="123456.png" alt="123456.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 17:34:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80222#M16245</guid>
      <dc:creator>Wang</dc:creator>
      <dc:date>2020-03-30T17:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80239#M16250</link>
      <description>A Custom Application/Site can only be used in an Application policy and column, where the get url command is compared to the URL in the custom Application.&lt;BR /&gt;A domain object is used in a source or destination field where the gateway does a resolution of the domain name to IP addresses and then looks if the IP hitting the gateway is in the domain resolution list.</description>
      <pubDate>Mon, 30 Mar 2020 20:34:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80239#M16250</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-30T20:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80252#M16253</link>
      <description>Okay, thank you very much. Is there an official document describing this problem?</description>
      <pubDate>Mon, 30 Mar 2020 23:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80252#M16253</guid>
      <dc:creator>Wang</dc:creator>
      <dc:date>2020-03-30T23:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80275#M16256</link>
      <description>this is not really a problem, these are just completely different approaches of how to allow something, the one is handled by the FW blade and the other by the URLF blade.</description>
      <pubDate>Tue, 31 Mar 2020 06:20:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80275#M16256</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-31T06:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80393#M16274</link>
      <description>For example, I want to visit ".checkpoint.com" to use the Domain for configuration or the Custom Applications/Sites creation URL？</description>
      <pubDate>Wed, 01 Apr 2020 02:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80393#M16274</guid>
      <dc:creator>Wang</dc:creator>
      <dc:date>2020-04-01T02:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80397#M16275</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For example, I want to visit ".checkpoint.com" to use the Domain for configuration or the Custom Applications/Sites creation URL？&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Test_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5274iD70F03896833A3FD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Test_1.png" alt="Test_1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Test_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5275i5FABC286925D4876/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Test_2.png" alt="Test_2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 02:31:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80397#M16275</guid>
      <dc:creator>Wang</dc:creator>
      <dc:date>2020-04-01T02:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80398#M16276</link>
      <description>If it is only the site checkpoint.com (and not &lt;A href="http://www.checkpoint.com" target="_blank"&gt;www.checkpoint.com&lt;/A&gt; or somethingelse.checkpoint.com), then you can use a FQDN Domain Object, as that works on being able to resolve checkpoint.com to an IP address.&lt;BR /&gt;Non-FQDN Domain Objects rely on being able to reverse-resolve the IP address being accessed to a name that has checkpoint.com in it.&lt;BR /&gt;This rarely works in the modern Internet.&lt;BR /&gt;&lt;BR /&gt;The App Control approach works for HTTP/HTTPS traffic.&lt;BR /&gt;For HTTPS sites, Categorize HTTPS Sites needs to be enabled and/or HTTPS Inspection must be enabled.&lt;BR /&gt;Categorize HTTPS Sites will work much better on R80.40 (or R80.20/R80.30 with latest GA JHF) due to added support for SNI.</description>
      <pubDate>Wed, 01 Apr 2020 02:43:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80398#M16276</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-01T02:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80405#M16277</link>
      <description>I'm very sorry, but I still don't understand. Could you tell me more details? Thank you very much。</description>
      <pubDate>Wed, 01 Apr 2020 03:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80405#M16277</guid>
      <dc:creator>Wang</dc:creator>
      <dc:date>2020-04-01T03:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80410#M16280</link>
      <description>&lt;P&gt;In very simple terms, a Domain Object attempts to make an association between a DNS name and an IP address.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;An FQDN Domain Object translates the FQDN to an IP address.&lt;/LI&gt;
&lt;LI&gt;A non-FQDN Domain Object confirms that an IP address is associated with a given domain by doing a &lt;A href="https://en.wikipedia.org/wiki/Reverse_DNS_lookup" target="_self"&gt;reverse DNS lookup&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can use a Domain Object in the rulebase similar to a host object that represents a single IP address.&lt;BR /&gt;As such, it can be used in a pure firewall rulebase without App Control or other advanced blades as it doesn't require any Layer 7 inspection.&lt;BR /&gt;The (reverse) DNS resolution effectively happens "out of band."&lt;/P&gt;
&lt;P&gt;This approach has a couple limitations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;These objects only work with IPv4, if I remember correctly.&lt;/LI&gt;
&lt;LI&gt;Many sites actually share the same IPv4 address and you'd be allowing (or blocking) all of those sites if you use these objects in a rule.&lt;/LI&gt;
&lt;LI&gt;Non-FQDN Domain Objects incur a fairly significant performance penalty and, in the end, usually doesn't work as the reverse DNS rarely matches the DNS name you're trying to match (if such records even exist at all).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;An Application/Site is effectively an App Control signature that operates at Layer 7.&lt;BR /&gt;It's a fairly simplistic App Control signature that identifies that traffic is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Web-based (i.e. regular HTTP or HTTPS)&lt;/LI&gt;
&lt;LI&gt;Is destined to&amp;nbsp;one of the domains you've listed in the definition.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the traffic is not web-based and/or App Control can't determine it's destined for one of the domains listed, then it will not match the traffic.&lt;/P&gt;
&lt;P&gt;There are reasons that both approaches are available.&lt;BR /&gt;You have to use the one that is appropriate for the problem you're trying to solve.&amp;nbsp;&lt;BR /&gt;The more information you can provide about your environment and precisely what your goal is, the more likely we can tell you what approach will work best.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 05:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80410#M16280</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-01T05:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80571#M16298</link>
      <description>Thank you very much for your reply</description>
      <pubDate>Thu, 02 Apr 2020 08:21:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/80571#M16298</guid>
      <dc:creator>Wang</dc:creator>
      <dc:date>2020-04-02T08:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81301#M16422</link>
      <description>&lt;P&gt;Hey Daemon, I should have asked you this one 20 years ago. &amp;nbsp;I kept meaning to test it to see how it operated, but it was never important enough to spend the time on.... I mean, who actually USES domain objects? &amp;nbsp;I have some follow up questions for clarity if I may...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When did the FQDN checkbox appear? &amp;nbsp;Was it always there?&lt;/LI&gt;&lt;LI&gt;I thought the prefixed "." differentiated whether it was a forward or reverse lookup... is this true?&lt;/LI&gt;&lt;LI&gt;Did it ALWAYS have both forward and reverse options?&lt;/LI&gt;&lt;LI&gt;With reverse lookup, when does the lookup take place? What process does it? &amp;nbsp;While the lookup is happening, is it a default match, no match, or are connections held?&lt;/LI&gt;&lt;LI&gt;Finally, any insight on why the third option is not provided that some other firewalls offer, which is to cache relevant forward lookups that the firewalls sees passing through and use them to inform a list of possible IP addresses?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks! Hope you're well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 10:45:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81301#M16422</guid>
      <dc:creator>Greg_Harewood</dc:creator>
      <dc:date>2020-04-08T10:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81359#M16432</link>
      <description>The FQDN checkbox (and related functionality) appeared in R80.10.&lt;BR /&gt;The . in front of the name also premiered in R80.10.&lt;BR /&gt;Without FQDN, the packet is held while the lookup takes place.&lt;BR /&gt;Don't recall what process is doing it.&lt;BR /&gt;Caching DNS lookups happening through the gateway is an R80.40 feature, but only to ones the gateway is configured to trust--either to same DNS server gateway uses or specific DNS objects created in SmartConsole.</description>
      <pubDate>Wed, 08 Apr 2020 18:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81359#M16432</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-08T18:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81404#M16441</link>
      <description>&lt;P&gt;Also, look here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165094" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165094&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sums up the case quite well&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/81404#M16441</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-09T07:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: The difference between checkpoint creation domain and Custom Applications/Sites creation URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/108519#M20659</link>
      <description>&lt;P&gt;Why hostnames are not supported by FQDN domain objects? So why I could create .checkpoint.com and not .community.checkpoint.com?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/The-difference-between-checkpoint-creation-domain-and-Custom/m-p/108519#M20659</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2021-01-22T14:01:26Z</dc:date>
    </item>
  </channel>
</rss>

