<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS requests from gateway for malicious websites in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113721#M21315</link>
    <description>&lt;P&gt;My guess is this is part of SNI verification, which happens even if you’re not doing HTTPS Inspection.&lt;BR /&gt;So, relevant for R80.30 JHF and above.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Mar 2021 20:06:50 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-16T20:06:50Z</dc:date>
    <item>
      <title>DNS requests from gateway for malicious websites</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113479#M21281</link>
      <description>&lt;P&gt;Dear CheckMates,&lt;/P&gt;
&lt;P&gt;sometimes we observed that the gateway does DNS requests to the configured DNS servers for malicious websites.&lt;BR /&gt;One of the sites as an example&amp;nbsp; is "&lt;A href="http://www.homng.net" target="_blank"&gt;www.homng.net&lt;/A&gt;".&lt;/P&gt;
&lt;P&gt;Why is the gateway trying to get the IP for malicious websites?&lt;BR /&gt;Any of the ThreatPrevention feature which does DNS requests sometimes for known malicious websites ?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;thanks&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 07:23:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113479#M21281</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-03-15T07:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNS requests from gateway for malicious websites</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113721#M21315</link>
      <description>&lt;P&gt;My guess is this is part of SNI verification, which happens even if you’re not doing HTTPS Inspection.&lt;BR /&gt;So, relevant for R80.30 JHF and above.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 20:06:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113721#M21315</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-16T20:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS requests from gateway for malicious websites</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113723#M21316</link>
      <description>&lt;P&gt;Hello Wolfgang&lt;/P&gt;&lt;P&gt;Maybe are you using Custom Intelligence Feeds (sk132193)?&lt;/P&gt;&lt;P&gt;BR,&lt;BR /&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 21:20:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-requests-from-gateway-for-malicious-websites/m-p/113723#M21316</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-03-16T21:20:11Z</dc:date>
    </item>
  </channel>
</rss>

