<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Reverse traffic is getting dropped in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87535#M17624</link>
    <description>I'd try: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92835" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92835&lt;/A&gt;&lt;BR /&gt;Note that even with IPS inactive, some of the protections under IPS are actually firewall protections.</description>
    <pubDate>Mon, 08 Jun 2020 03:05:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-06-08T03:05:49Z</dc:date>
    <item>
      <title>DNS Reverse traffic is getting dropped</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87286#M17528</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is checkpoint clusterXL in load sharing mode and its still on R77.30. We have our NS servers configured behind firewall, however recently we started observing lot of SERVFAIL messages on DNS server and hence started troubleshooting. Eventually when we done fw ctl zdebug drop we found that server when sending Recusrsive queries to Root Hint server the response is getting dropped on Stealth rule.&lt;/P&gt;&lt;P&gt;Surprisingly why it would drop response from Root Hint servers. Now there are not blades running on firewall but only fw. No IPS/AMW nothing.&lt;/P&gt;&lt;P&gt;Here are the logs - and a.b.c.d is my Natted Public IP of my DNS server. Rule #47 is a stealth rule&lt;/P&gt;&lt;P&gt;4Jun2020 15:07:44.407985;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=17 103.204.163.83:48073 -&amp;gt; a.b.c.d:53 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 47;&lt;BR /&gt;4Jun2020 15:07:44.423727;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=17 103.204.163.80:47955 -&amp;gt; a.b.c.d:53 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 47;&lt;BR /&gt;4Jun2020 15:07:44.426534;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 103.204.163.66:45982 -&amp;gt; a.b.c.d:53 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 47;&lt;BR /&gt;4Jun2020 15:07:44.450732;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=17 103.204.163.65:42568 -&amp;gt; a.b.c.d:53 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 47;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 10:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87286#M17528</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2020-06-04T10:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reverse traffic is getting dropped</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87535#M17624</link>
      <description>I'd try: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92835" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92835&lt;/A&gt;&lt;BR /&gt;Note that even with IPS inactive, some of the protections under IPS are actually firewall protections.</description>
      <pubDate>Mon, 08 Jun 2020 03:05:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87535#M17624</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-08T03:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reverse traffic is getting dropped</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87786#M17687</link>
      <description>&lt;P&gt;Any way we figured that out and that is due to ClusterXL load sharing and wrong switch configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 17:42:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87786#M17687</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2020-06-09T17:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reverse traffic is getting dropped</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87804#M17689</link>
      <description>Hi so you are saying it was a wrongly configured switch that was causing the drops?</description>
      <pubDate>Tue, 09 Jun 2020 22:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87804#M17689</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-06-09T22:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Reverse traffic is getting dropped</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87821#M17697</link>
      <description>&lt;P&gt;Yes this is what there network team told me. Sicne I do not have access to those switches if pretty tough to say what changes they made &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 03:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Reverse-traffic-is-getting-dropped/m-p/87821#M17697</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2020-06-10T03:56:23Z</dc:date>
    </item>
  </channel>
</rss>

