<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CP Firewall - Traffic Accepted - Domain resolving error. Check DNS configuration on the gateway (0) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93627#M18555</link>
    <description>&lt;P&gt;Hi, whilst reviewing the firewall logs for a VPN failure I found a series of accept, type - alert/connection messages. We have multiple VPNS running on this firewall and I found 23,000 connection alerts in one day for VPN blades. We are running a pair of 4800 firewalls running Checkpoint R80.30 for our external facing firewall. I am not sure if this traffic is actually failing, its traffic traversing a VPN tunnel so I would expect decrypt/encrypt messages rather than accept. Under the log Entry Blade VPN Product Family Access Type Connection/Alert Action Allow Reason Firewall - Domain resolving error, Check DNS configuration on the gateway (0) The majority of the traffic that we have this error with is VPN traffic, however there are some other entries, one this morning for an outbound IKE connection from an internal VPN router to a remote VPN router I have attempted to upload images but it wont work from my works desktop, I will try to add them elsewhere. Any help would be appreciated. Regards Cass&lt;/P&gt;</description>
    <pubDate>Fri, 07 Aug 2020 08:28:05 GMT</pubDate>
    <dc:creator>CassSH__</dc:creator>
    <dc:date>2020-08-07T08:28:05Z</dc:date>
    <item>
      <title>CP Firewall - Traffic Accepted - Domain resolving error. Check DNS configuration on the gateway (0)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93627#M18555</link>
      <description>&lt;P&gt;Hi, whilst reviewing the firewall logs for a VPN failure I found a series of accept, type - alert/connection messages. We have multiple VPNS running on this firewall and I found 23,000 connection alerts in one day for VPN blades. We are running a pair of 4800 firewalls running Checkpoint R80.30 for our external facing firewall. I am not sure if this traffic is actually failing, its traffic traversing a VPN tunnel so I would expect decrypt/encrypt messages rather than accept. Under the log Entry Blade VPN Product Family Access Type Connection/Alert Action Allow Reason Firewall - Domain resolving error, Check DNS configuration on the gateway (0) The majority of the traffic that we have this error with is VPN traffic, however there are some other entries, one this morning for an outbound IKE connection from an internal VPN router to a remote VPN router I have attempted to upload images but it wont work from my works desktop, I will try to add them elsewhere. Any help would be appreciated. Regards Cass&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 08:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93627#M18555</guid>
      <dc:creator>CassSH__</dc:creator>
      <dc:date>2020-08-07T08:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: CP Firewall - Traffic Accepted - Domain resolving error. Check DNS configuration on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93696#M18566</link>
      <description>&lt;P&gt;What is the precise rule(s) that are accepting this traffic?&lt;BR /&gt;Do they contain Domain or Updatable Objects by chance?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 04:25:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93696#M18566</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-09T04:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: CP Firewall - Traffic Accepted - Domain resolving error. Check DNS configuration on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93739#M18576</link>
      <description>&lt;P&gt;There are multiple rules that show traffic being accepted and generating alerts. However they are predominantly VPN rules and the rule one that started this is for VPN community traffic to allow our amazon hosted web services to talk to a internal datapower device.&amp;nbsp; In this example the source is defined as a network range and the destination is defined as a host with a&amp;nbsp;statically assigned address on our device.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpnlogs.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7552i6795289B7CC6D238/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vpnlogs.png" alt="vpnlogs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7551iE760DE5C01F3B398/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rule.jpg" alt="rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; For information we are using updatable objects, custom applications and domain objects in other rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Cass&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 07:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP-Firewall-Traffic-Accepted-Domain-resolving-error-Check-DNS/m-p/93739#M18576</guid>
      <dc:creator>CassSH__</dc:creator>
      <dc:date>2020-08-10T07:11:59Z</dc:date>
    </item>
  </channel>
</rss>

