<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS traffic is not passing through firewall in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95883#M18879</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20795"&gt;@Harish_Sankaran&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;use the following cli commands&lt;BR /&gt;&lt;FONT color="#FF00FF"&gt;fw ctl zdebug drop | grep &lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&amp;lt;source IP&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;or&lt;BR /&gt;&lt;FONT color="#FF00FF"&gt;fw monitor -e "accept( host=&lt;STRONG&gt;&amp;lt;source IP&amp;gt;&lt;/STRONG&gt;);"&lt;/FONT&gt;&lt;BR /&gt;to debug the traffic flow.&lt;/P&gt;
&lt;P&gt;More to "fw monitor" could you found here:&lt;BR /&gt;&lt;A class="jive-link-wiki-small" href="https://community.checkpoint.com/docs/DOC-3475-r8020-update-cheat-sheet-fw-monitor" target="_blank" rel="noopener" data-containerid="2057" data-containertype="14" data-objectid="3475" data-objecttype="102"&gt;R80.x - cheat sheet - fw monitor&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 19:15:36 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2020-09-02T19:15:36Z</dc:date>
    <item>
      <title>DNS traffic is not passing through firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95818#M18865</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to do nslook-up from out side through URL.We want see the traffic from the URL.&lt;/P&gt;&lt;P&gt;a)Any end user NSLOOKUP request coming from internet hitting website,&amp;nbsp; It does not show logs in Firewall. Hence we are not able to detect connections as well as source IP address. We need detailed logs indicating NSLOOKUP request flow as well as Source IP details.&lt;/P&gt;&lt;P&gt;b)Is there any mode in Firewall for detailed log analysis. Currently limited logs are visible which may not be enough for any forensics if required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 07:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95818#M18865</guid>
      <dc:creator>Harish_Sankaran</dc:creator>
      <dc:date>2020-09-02T07:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic is not passing through firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95883#M18879</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20795"&gt;@Harish_Sankaran&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;use the following cli commands&lt;BR /&gt;&lt;FONT color="#FF00FF"&gt;fw ctl zdebug drop | grep &lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&amp;lt;source IP&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/STRONG&gt;or&lt;BR /&gt;&lt;FONT color="#FF00FF"&gt;fw monitor -e "accept( host=&lt;STRONG&gt;&amp;lt;source IP&amp;gt;&lt;/STRONG&gt;);"&lt;/FONT&gt;&lt;BR /&gt;to debug the traffic flow.&lt;/P&gt;
&lt;P&gt;More to "fw monitor" could you found here:&lt;BR /&gt;&lt;A class="jive-link-wiki-small" href="https://community.checkpoint.com/docs/DOC-3475-r8020-update-cheat-sheet-fw-monitor" target="_blank" rel="noopener" data-containerid="2057" data-containertype="14" data-objectid="3475" data-objecttype="102"&gt;R80.x - cheat sheet - fw monitor&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 19:15:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95883#M18879</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-09-02T19:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic is not passing through firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95888#M18880</link>
      <description>&lt;P&gt;I don't really see what you are trying to identify here. When I use nslookup to resolve a URL like:&lt;/P&gt;
&lt;P&gt;nslookup &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;all that will happen is that my machine will contact the configured DNS server and ask the question at which IP I can reach &lt;A href="http://www.google.com," target="_blank"&gt;www.google.com,&lt;/A&gt;&amp;nbsp;nslookup will not send any packet to &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&amp;nbsp;itself.&lt;/P&gt;
&lt;P&gt;Extended logging can be set by enabling accounting.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 21:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-traffic-is-not-passing-through-firewall/m-p/95888#M18880</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-09-02T21:14:23Z</dc:date>
    </item>
  </channel>
</rss>

