<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Resolution failing but ping to IP address is succesful. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104674#M20102</link>
    <description>&lt;P&gt;So how do you expect packets to get back then?&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 16:00:28 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-12-08T16:00:28Z</dc:date>
    <item>
      <title>DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104661#M20098</link>
      <description>&lt;P&gt;I have set up a lab where CP machines are in Cluster XL(HA). From my virtual windows machine i can ping my dns server on the internet but when trying to open google etc its not opening. I have all the policies in place. Am i missing something ?&lt;/P&gt;&lt;P&gt;Topology Diag attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the config&lt;/P&gt;&lt;P&gt;R1:&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0 ---&amp;gt;Interface connected Cloud&lt;BR /&gt;ip address dhcp&lt;BR /&gt;ip nat outside&lt;BR /&gt;duplex full&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1/0--&amp;gt;Interface connected Gateway&lt;BR /&gt;ip address 1.1.1.4 255.255.255.0&lt;BR /&gt;ip nat inside&lt;BR /&gt;duplex full&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip route 192.168.1.0 255.255.255.0 1.1.1.254 --&amp;gt;(1.1.1.254 is virtual ip of gateway eth1 i.e external interface)dd&lt;BR /&gt;!&lt;BR /&gt;access-list 1 permit 1.1.1.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 2.2.2.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 192.168.1.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;r1#ping google.com&lt;BR /&gt;Translating "google.com"...domain server (150.129.130.254) [OK]&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 142.250.76.206, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/9/12 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint has default route configured for which next hop is router&lt;/P&gt;&lt;P&gt;Gateway1&amp;gt; show route&lt;BR /&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt;O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt;A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;S 0.0.0.0/0 via 1.1.1.4, eth1, cost 0, age 17116&amp;nbsp; (1.1.1.4 is router fa1/0 ip)&lt;BR /&gt;C 1.1.1.0/24 is directly connected, eth1&lt;BR /&gt;External&lt;BR /&gt;C 127.0.0.0/8 is directly connected, lo&lt;BR /&gt;C 172.16.1.0/30 is directly connected, eth2&lt;BR /&gt;C 172.16.254.0/24 is directly connected, eth3&lt;BR /&gt;C 192.168.1.0/24 is directly connected, eth0&lt;BR /&gt;Internal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried a lot but failed, i would really appreciated if someone could help pls.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 14:30:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104661#M20098</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T14:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104662#M20099</link>
      <description>&lt;P&gt;unable to open any website from virtual machine&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 14:31:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104662#M20099</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T14:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104671#M20100</link>
      <description>&lt;P&gt;Check you have proper NAT and accept rules in place&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 15:27:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104671#M20100</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-08T15:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104672#M20101</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;There is no NAT on firewall. And from source 192.168.1.0/24 to ANY have https,http,dns etc allowed in policy. Snap attached for same.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 15:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104672#M20101</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T15:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104674#M20102</link>
      <description>&lt;P&gt;So how do you expect packets to get back then?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:00:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104674#M20102</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-08T16:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104678#M20104</link>
      <description>&lt;P&gt;Router is performing NAT. Please see below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ip route 192.168.1.0 255.255.255.0 1.1.1.254 --&amp;gt;(1.1.1.254 is virtual ip of cluster i.e external interface)&lt;BR /&gt;!&lt;BR /&gt;access-list 1 permit 1.1.1.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 2.2.2.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 192.168.1.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;r1#sh ip route&lt;BR /&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt;D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;E1 - OSPF external type 1, E2 - OSPF external type 2&lt;BR /&gt;i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt;ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt;o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP&lt;BR /&gt;+ - replicated route, % - next hop override&lt;/P&gt;&lt;P&gt;Gateway of last resort is 192.168.0.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;S* 0.0.0.0/0 [254/0] via 192.168.0.1&lt;BR /&gt;1.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;BR /&gt;C 1.1.1.0/24 is directly connected, FastEthernet1/0&lt;BR /&gt;L 1.1.1.4/32 is directly connected, FastEthernet1/0&lt;BR /&gt;192.168.0.0/24 is variably subnetted, 2 subnets, 2 masks&lt;BR /&gt;C 192.168.0.0/24 is directly connected, FastEthernet0/0&lt;BR /&gt;L 192.168.0.13/32 is directly connected, FastEthernet0/0&lt;BR /&gt;S 192.168.1.0/24 [1/0] via 1.1.1.254&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104678#M20104</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T16:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104681#M20105</link>
      <description>&lt;P&gt;Then another question. Do you have this internal network define on your external router, so it could return packets to FW correctly?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:19:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104681#M20105</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-08T16:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104688#M20108</link>
      <description>&lt;P&gt;yes, there is static route "&lt;SPAN&gt;S 192.168.1.0/24 [1/0] via 1.1.1.254". Also in access-list those ip's are mentioned&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list 1 permit 1.1.1.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 2.2.2.0 0.0.0.255&lt;BR /&gt;access-list 1 permit 192.168.1.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Although there is no need of 1.1.1.0/24 &amp;amp; 2.2.2.0/24 in acl. But still i have those. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My system ip is 192.168.1.4 and gateway is 192.168.1.254. Cluster virtual ip is 192.168.1.254. So when packet goes out from system to Def GW-192.168.1.254. As soon as it hits virtual ip, active FW will process that. Now there is default route on FW it forwards it to router .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When packet arrives on router it has default route for internet and also in access-list (in which 192.168.1.0/24) is allowed. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For return traffic there is static route for 192.168.1.0/24 for which next hop is 1.1.1.254 (virtual ip). Active fw should process it and should forward to windows machine&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104688#M20108</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T16:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104689#M20109</link>
      <description>&lt;P&gt;run fw monitor on the GW to see what's going on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 16:51:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104689#M20109</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-08T16:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104692#M20110</link>
      <description>&lt;P&gt;When i did nslookup google.com also tried opening google.com&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=74 id=13884&lt;BR /&gt;UDP: 52652 -&amp;gt; 53&lt;BR /&gt;[vs_0][fw_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=74 id=13884&lt;BR /&gt;UDP: 52652 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=74 id=13884&lt;BR /&gt;UDP: 52652 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth0:I[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=74 id=13884&lt;BR /&gt;UDP: 52652 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth1:o[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=74 id=13884&lt;BR /&gt;UDP: 52652 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth1:O[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=74 id=13884&lt;BR /&gt;UDP: 52652 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth1:i[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2865&lt;BR /&gt;ICMP: type=3 code=1 unreachable (host)&lt;BR /&gt;[vs_0][fw_0] eth1:i[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2865&lt;BR /&gt;ICMP: type=3 code=1 unreachable (host)&lt;BR /&gt;[vs_0][fw_0] eth1:I[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2865&lt;BR /&gt;ICMP: type=3 code=1 unreachable (host)&lt;BR /&gt;[vs_0][fw_0] eth0:o[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2865&lt;BR /&gt;ICMP: type=3 code=1 unreachable (host)&lt;BR /&gt;[vs_0][fw_0] eth0:O[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2865&lt;BR /&gt;ICMP: type=3 code=1 unreachable (host)&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=56 id=13891&lt;BR /&gt;UDP: 52653 -&amp;gt; 53&lt;BR /&gt;[vs_0][fw_1] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=56 id=13891&lt;BR /&gt;UDP: 52653 -&amp;gt; 53&lt;BR /&gt;[vs_0][fw_2] eth0:o[44]: 192.168.1.1 -&amp;gt; 192.168.1.3 (TCP) len=186 id=55605&lt;BR /&gt;TCP: 63910 -&amp;gt; 257 ...PA. seq=95a379c8 ack=1326e0ad&lt;BR /&gt;[vs_0][fw_2] eth0:O[44]: 192.168.1.1 -&amp;gt; 192.168.1.3 (TCP) len=186 id=55605&lt;BR /&gt;TCP: 63910 -&amp;gt; 257 ...PA. seq=95a379c8 ack=1326e0ad&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=56 id=13891&lt;BR /&gt;UDP: 52653 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth0:I[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=56 id=13891&lt;BR /&gt;UDP: 52653 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth1:o[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=56 id=13891&lt;BR /&gt;UDP: 52653 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth1:O[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (UDP) len=56 id=13891&lt;BR /&gt;UDP: 52653 -&amp;gt; 53&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.3 -&amp;gt; 192.168.1.1 (TCP) len=52 id=45307&lt;BR /&gt;TCP: 257 -&amp;gt; 63910 ....A. seq=1326e0ad ack=95a37a4e&lt;BR /&gt;[vs_0][fw_2] eth0:i[44]: 192.168.1.3 -&amp;gt; 192.168.1.1 (TCP) len=52 id=45307&lt;BR /&gt;TCP: 257 -&amp;gt; 63910 ....A. seq=1326e0ad ack=95a37a4e&lt;BR /&gt;[vs_0][fw_2] eth0:I[44]: 192.168.1.3 -&amp;gt; 192.168.1.1 (TCP) len=52 id=45307&lt;BR /&gt;TCP: 257 -&amp;gt; 63910 ....A. seq=1326e0ad ack=95a37a4e&lt;BR /&gt;[vs_0][ppak_0] eth1:i[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2866&lt;BR /&gt;ICMP: type=3 code=1 unreachable (host)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i tried to ping both DNS server&lt;/P&gt;&lt;P&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13992&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13992&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth0:I[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13992&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth1:o[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13992&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth1:O[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13992&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=81&lt;BR /&gt;[vs_0][ppak_0] eth1:i[44]: 150.129.130.254 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=43695&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth1:i[44]: 150.129.130.254 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=43695&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth1:I[44]: 150.129.130.254 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=43695&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth0:o[44]: 150.129.130.254 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=43695&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=81&lt;BR /&gt;[vs_0][fw_1] eth0:O[44]: 150.129.130.254 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=43695&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=81&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13993&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=82&lt;BR /&gt;[vs_0][fw_1] eth0:i[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13993&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=82&lt;BR /&gt;[vs_0][fw_1] eth0:I[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13993&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=82&lt;BR /&gt;[vs_0][fw_1] eth1:o[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13993&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=82&lt;BR /&gt;[vs_0][fw_1] eth1:O[44]: 192.168.1.4 -&amp;gt; 150.129.130.254 (ICMP) len=60 id=13993&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17867&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17867&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth0:I[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17867&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth1:o[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17867&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth1:O[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17867&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=87&lt;BR /&gt;[vs_0][ppak_0] eth1:i[44]: 8.8.8.8 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=0&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth1:i[44]: 8.8.8.8 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=0&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth1:I[44]: 8.8.8.8 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=0&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth0:o[44]: 8.8.8.8 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=0&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=87&lt;BR /&gt;[vs_0][fw_0] eth0:O[44]: 8.8.8.8 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=0&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=87&lt;BR /&gt;[vs_0][fw_2] eth0:o[44]: 192.168.1.1 -&amp;gt; 192.168.1.3 (TCP) len=194 id=55695&lt;BR /&gt;TCP: 63910 -&amp;gt; 257 ...PA. seq=95a3d486 ack=1326e0c7&lt;BR /&gt;[vs_0][fw_2] eth0:O[44]: 192.168.1.1 -&amp;gt; 192.168.1.3 (TCP) len=194 id=55695&lt;BR /&gt;TCP: 63910 -&amp;gt; 257 ...PA. seq=95a3d486 ack=1326e0c7&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.3 -&amp;gt; 192.168.1.1 (TCP) len=52 id=45397&lt;BR /&gt;TCP: 257 -&amp;gt; 63910 ....A. seq=1326e0c7 ack=95a3d514&lt;BR /&gt;[vs_0][fw_2] eth0:i[44]: 192.168.1.3 -&amp;gt; 192.168.1.1 (TCP) len=52 id=45397&lt;BR /&gt;TCP: 257 -&amp;gt; 63910 ....A. seq=1326e0c7 ack=95a3d514&lt;BR /&gt;[vs_0][fw_2] eth0:I[44]: 192.168.1.3 -&amp;gt; 192.168.1.1 (TCP) len=52 id=45397&lt;BR /&gt;TCP: 257 -&amp;gt; 63910 ....A. seq=1326e0c7 ack=95a3d514&lt;BR /&gt;[vs_0][ppak_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17868&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=88&lt;BR /&gt;[vs_0][fw_0] eth0:i[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17868&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=88&lt;BR /&gt;[vs_0][fw_0] eth0:I[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17868&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=88&lt;BR /&gt;[vs_0][fw_0] eth1:o[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17868&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=88&lt;BR /&gt;[vs_0][fw_0] eth1:O[44]: 192.168.1.4 -&amp;gt; 8.8.8.8 (ICMP) len=60 id=17868&lt;BR /&gt;ICMP: type=8 code=0 echo request id=1 seq=88&lt;BR /&gt;[vs_0][ppak_0] eth1:i[44]: 8.8.8.8 -&amp;gt; 192.168.1.4 (ICMP) len=60 id=0&lt;BR /&gt;ICMP: type=0 code=0 echo reply id=1 seq=88&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 17:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104692#M20110</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T17:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104693#M20111</link>
      <description>&lt;P&gt;Logs when i did tcpdump&lt;/P&gt;&lt;P&gt;23:00:17.263816 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:17.363774 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:17.764018 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:17.864018 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:18.264152 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:18.264453 STP 802.1d, Config, Flags [none], bridge-id 8001.aa:bb:cc:01:20:00.8001, length 43&lt;BR /&gt;23:00:18.364301 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:18.764406 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:18.864581 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:19.264581 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:19.364724 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:19.511287 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [.], seq 1123360406:1123361854, ack 846767005, win 76, options [nop,nop,TS val 28654509 ecr 27500058], length 1448&lt;BR /&gt;23:00:19.511344 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [.], seq 1448:2896, ack 1, win 76, options [nop,nop,TS val 28654509 ecr 27500058], length 1448&lt;BR /&gt;23:00:19.511361 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [.], seq 2896:4344, ack 1, win 76, options [nop,nop,TS val 28654509 ecr 27500058], length 1448&lt;BR /&gt;23:00:19.511377 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [.], seq 4344:5792, ack 1, win 76, options [nop,nop,TS val 28654509 ecr 27500058], length 1448&lt;BR /&gt;23:00:19.511731 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 1448, win 173, options [nop,nop,TS val 27520077 ecr 28654509], length 0&lt;BR /&gt;23:00:19.511752 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 2896, win 173, options [nop,nop,TS val 27520077 ecr 28654509], length 0&lt;BR /&gt;23:00:19.511754 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 4344, win 172, options [nop,nop,TS val 27520077 ecr 28654509], length 0&lt;BR /&gt;23:00:19.511756 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 5792, win 171, options [nop,nop,TS val 27520077 ecr 28654509], length 0&lt;BR /&gt;23:00:19.511867 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [.], seq 5792:7240, ack 1, win 76, options [nop,nop,TS val 28654510 ecr 27520077], length 1448&lt;BR /&gt;23:00:19.511895 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [.], seq 7240:8688, ack 1, win 76, options [nop,nop,TS val 28654510 ecr 27520077], length 1448&lt;BR /&gt;23:00:19.511911 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [P.], seq 8688:9318, ack 1, win 76, options [nop,nop,TS val 28654510 ecr 27520077], length 630&lt;BR /&gt;23:00:19.512078 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 7240, win 173, options [nop,nop,TS val 27520077 ecr 28654510], length 0&lt;BR /&gt;23:00:19.512088 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 8688, win 173, options [nop,nop,TS val 27520077 ecr 28654510], length 0&lt;BR /&gt;23:00:19.512090 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 9318, win 173, options [nop,nop,TS val 27520077 ecr 28654510], length 0&lt;BR /&gt;23:00:19.764714 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:19.792412 IP 192.168.1.4.56676 &amp;gt; 150.129.130.254.domain: 17982+ A? google.com. (28)&lt;BR /&gt;23:00:19.792461 IP 192.168.1.4.56676 &amp;gt; 8.8.8.8.domain: 17982+ A? google.com. (28)&lt;BR /&gt;23:00:19.801208 IP 1.1.1.4 &amp;gt; 192.168.1.4: ICMP host 150.129.130.254 unreachable, length 36&lt;BR /&gt;23:00:19.864868 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:20.264864 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:20.265165 STP 802.1d, Config, Flags [none], bridge-id 8001.aa:bb:cc:01:20:00.8001, length 43&lt;BR /&gt;23:00:20.365049 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:20.765076 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:20.865233 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:21.265219 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:21.365396 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:21.765440 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:21.865561 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:22.265571 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:22.265922 STP 802.1d, Config, Flags [none], bridge-id 8001.aa:bb:cc:01:20:00.8001, length 43&lt;BR /&gt;23:00:22.365867 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:22.749761 DTPv1, length 34&lt;/P&gt;&lt;P&gt;23:00:22.749763 aa:bb:cc:01:20:00 (oui Unknown) &amp;gt; 01:00:0c:00:00:00 (oui Unknown) SNAP, oui Cisco (0x00000c), pid Unknown (0x0003), length 68:&lt;BR /&gt;0x0000: aaaa 0300 000c 0003 0000 0000 0100 0ccc ................&lt;BR /&gt;0x0010: cccc aabb cc01 2000 0022 aaaa 0300 000c ........."......&lt;BR /&gt;0x0020: 2004 0100 0100 0500 0002 0005 0300 0300 ................&lt;BR /&gt;0x0030: 0540 0004 000a aabb cc01 2000 f82d 743f .@...........-t?&lt;BR /&gt;0x0040: 5d64 8010 0020 cfc8 098c a939 ]d.........9&lt;BR /&gt;23:00:22.765751 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:22.865999 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:23.265869 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:23.366141 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:23.766146 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:23.792623 IP 192.168.1.4.netbios-ns &amp;gt; 192.168.1.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST&lt;BR /&gt;23:00:23.866196 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:24.266290 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:24.266590 STP 802.1d, Config, Flags [none], bridge-id 8001.aa:bb:cc:01:20:00.8001, length 43&lt;BR /&gt;23:00:24.366502 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:24.515407 IP Gateway1.18192 &amp;gt; 192.168.1.3.57607: Flags [P.], seq 9318:9432, ack 1, win 76, options [nop,nop,TS val 28659513 ecr 27520077], length 114&lt;BR /&gt;23:00:24.515859 IP 192.168.1.3.57607 &amp;gt; Gateway1.18192: Flags [.], ack 9432, win 173, options [nop,nop,TS val 27525081 ecr 28659513], length 0&lt;BR /&gt;23:00:24.542422 IP 192.168.1.4.netbios-ns &amp;gt; 192.168.1.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST&lt;BR /&gt;23:00:24.766570 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:24.809401 ARP, Request who-has 192.168.1.4 tell Gateway1, length 28&lt;BR /&gt;23:00:24.809742 ARP, Reply 192.168.1.4 is-at 50:00:00:2f:00:00 (oui Unknown), length 46&lt;BR /&gt;23:00:24.866669 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:25.266787 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:25.292372 IP 192.168.1.4.netbios-ns &amp;gt; 192.168.1.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST&lt;BR /&gt;23:00:25.366939 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:25.766988 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:25.867062 ARP, Request who-has 192.168.1.254 tell 192.168.1.254, length 28&lt;BR /&gt;23:00:25.867274 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:26.094161 IP Gateway1.63910 &amp;gt; 192.168.1.3.set: Flags [P.], seq 246:384, ack 1, win 40, options [nop,nop,TS val 28661092 ecr 27514659], length 138&lt;BR /&gt;23:00:26.094624 IP 192.168.1.3.set &amp;gt; Gateway1.63910: Flags [.], ack 384, win 174, options [nop,nop,TS val 27526660 ecr 28661092], length 0&lt;BR /&gt;23:00:26.265915 STP 802.1d, Config, Flags [none], bridge-id 8001.aa:bb:cc:01:20:00.8001, length 43&lt;BR /&gt;23:00:26.267365 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:26.367578 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:26.767639 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:26.867433 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:27.267747 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:27.367630 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:27.767864 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:27.867671 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:28.265849 STP 802.1d, Config, Flags [none], bridge-id 8001.aa:bb:cc:01:20:00.8001, length 43&lt;BR /&gt;23:00:28.267936 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:28.367938 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:28.768073 IP Gateway1.cp-cluster &amp;gt; 192.168.1.2.cp-cluster: UDP, length 50&lt;BR /&gt;23:00:28.868040 IP 192.168.1.2.cp-cluster &amp;gt; Gateway1.cp-cluster: UDP, length 50&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 17:36:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104693#M20111</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-08T17:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104694#M20112</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;From my understanding the VM ( 192.168.1.4 ) is in the 192.168.1.0 /24 network , which has a GW of .254 .&lt;/P&gt;
&lt;P&gt;The firewall cluster has a default route towards 1.1.1.4, R1 where there is a ACL which would say that traffic coming from 1.1.1.0 /24 , 2.2.2.0 /24 and 192.168.1.0 /24 should be PAT-ed with the interface IP of Fa0/0. Correct so far ?&lt;/P&gt;
&lt;P&gt;When you do a traceroute towards 8.8.8.8 from the VM, where does the traffic stop ?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 18:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104694#M20112</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-12-08T18:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104728#M20114</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36091"&gt;@funkylicious&lt;/a&gt;&amp;nbsp;&lt;SPAN&gt;The firewall cluster has a default route towards 1.1.1.4, R1 where there is a ACL which would say that traffic coming from 1.1.1.0 /24 , 2.2.2.0 /24 and 192.168.1.0 /24 should be PAT-ed with the interface IP of Fa0/0. Correct so far ? ---&amp;gt;Yes you are correct&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you do a traceroute towards 8.8.8.8 from the VM, where does the traffic stop ?--&amp;gt;Please find the attached snap&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 07:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104728#M20114</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-09T07:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104729#M20115</link>
      <description>&lt;P&gt;Something is blocking your DNS traffic outside of FW, can't you see?&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;[vs_0][ppak_0] eth1:i[44]: 1.1.1.4 -&amp;gt; 192.168.1.4 (ICMP) len=56 id=2866&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ICMP: type=3 code=1 unreachable (host)&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 08:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/104729#M20115</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-09T08:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/105005#M20154</link>
      <description>&lt;P&gt;Ok, from my understanding your traceroute/icmp goes through but your DNS/web requests are not.&lt;/P&gt;
&lt;P&gt;From R1 directly, can you please try a telnet towards &lt;A href="http://www.google.com" target="_blank" rel="noopener"&gt;www.google.com&lt;/A&gt;&amp;nbsp;on ports 80 and 443 ?&lt;/P&gt;
&lt;P&gt;Also, can you please check the Internet settings in your browser ? Maybe also try a telnet/portqry from the VM towards 80 and 443 ?&lt;/P&gt;
&lt;P&gt;If these are not working either, I&amp;nbsp; suspect that something is off between your router and EVE-NG cloud NET, which connects to your host/real Network.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 15:29:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/105005#M20154</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-12-10T15:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution failing but ping to IP address is succesful.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/105116#M20175</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36091"&gt;@funkylicious&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From router its working already&lt;/P&gt;&lt;P&gt;r1#ping google.com&lt;BR /&gt;Translating "google.com"...domain server (150.129.130.254) [OK]&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 142.250.76.206, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/14/24 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After lot of troubleshooting, finally i found the solution. Static NAT worked !!. Now second question is why overload wasn't working at all. May be i have to check with cisco&lt;/P&gt;&lt;P&gt;There was only one statement on router which was doing interface PAT.&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Fa0/0 connected to EVE cloud which represent real NIC, which is my physical system NIC. Router fa0/0 and physical system NIC are on same subnet 192.168.0.0/24)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change i did on router:&lt;/P&gt;&lt;P&gt;I removed PAT statement and added static NAT entry.&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.1.4 192.168.0.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 09:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-Resolution-failing-but-ping-to-IP-address-is-succesful/m-p/105116#M20175</guid>
      <dc:creator>Nick_Shah</dc:creator>
      <dc:date>2020-12-11T09:25:06Z</dc:date>
    </item>
  </channel>
</rss>

