<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: custom url query in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118284#M22005</link>
    <description>&lt;P&gt;ok i did as you suggested, this is how the rule looks:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inkedfqdn_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11678i47B84DD1CBC171D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Inkedfqdn_LI.jpg" alt="Inkedfqdn_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the fqdn box is checked on that object.&lt;/P&gt;&lt;P&gt;Now i&amp;nbsp; need to find a way to test it out and if its working will update here thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 17:56:06 GMT</pubDate>
    <dc:creator>kb1</dc:creator>
    <dc:date>2021-05-12T17:56:06Z</dc:date>
    <item>
      <title>custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117943#M21947</link>
      <description>&lt;P&gt;So we have a url whose ip changes frequently and im not able to make a working rule to for the url. The url uses a specific port as well and in the rule there are 2 specific source ips.&lt;/P&gt;&lt;P&gt;Ive tried the following rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inkedrule_LI.jpg" style="width: 614px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11634iD345172A58B2BF11/image-dimensions/614x345?v=v2" width="614" height="345" role="button" title="Inkedrule_LI.jpg" alt="Inkedrule_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the ems2.swims.faa.gov object looks as shown below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="obj.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11635i236834953F269082/image-size/large?v=v2&amp;amp;px=999" role="button" title="obj.png" alt="obj.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So as you can see in the pic above i have used "*.ems2.swim.faa.gov", i just changed it to this expression and do not know if this one will work as we haven't tested it yet, the previous expression i used was "ems2.swim.faa.gov" which did not work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now if the expression used above also doesn't work what should i use to make it work?&lt;/P&gt;&lt;P&gt;Note that https inspection is not enabled but categorize https inspection is enabled.&lt;/P&gt;&lt;P&gt;Firewall cluster is running on R80.20 with cpinfo -y all shown below:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cpinfo -y all&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This is Check Point CPinfo Build 914000202 for GAIA&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;[IDA]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;No hotfixes..&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[CPFC]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[MGMT]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[FW1]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_MAAS_TUNNEL_AUTOUPDATE&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FW1 build number:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;This is Check Point's software version R80.20 - Build 163&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;kernel: R80.20 - Build 151&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[SecurePlatform]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[CPinfo]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;No hotfixes..&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[PPACK]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[DIAG]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;No hotfixes..&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[CVPN]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_ESOD_SCANNER_AUTOUPDATE&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_ESOD_CSHELL_AUTOUPDATE&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_ESOD_SWS_AUTOUPDATE&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[CPUpdates]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_HCP_AUTOUPDATE Take: 29&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_ESOD_SCANNER_AUTOUPDATE Take: 9&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_ESOD_CSHELL_AUTOUPDATE Take: 13&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_ESOD_SWS_AUTOUPDATE Take: 14&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_MAAS_TUNNEL_AUTOUPDATE Take: 53&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_INFRA_AUTOUPDATE Take: 41&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_DEP_INSTALLER_AUTOUPDATE Take: 23&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;BUNDLE_R80_20_JUMBO_HF_MAIN Take: 118&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[CPDepInst]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;No hotfixes..&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[AutoUpdater]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;No hotfixes..&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[hcp_wrapper]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;HOTFIX_HCP_AUTOUPDATE&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Also there is another rule which is being used to block traffic to Microsoft URLs as shown below and it works:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inkedmicroso_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11636i92D44F944AACD339/image-size/large?v=v2&amp;amp;px=999" role="button" title="Inkedmicroso_LI.jpg" alt="Inkedmicroso_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The "Block custom URLs" object looks as shown below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ob.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11637i6416E07FF848FCE1/image-size/large?v=v2&amp;amp;px=999" role="button" title="ob.png" alt="ob.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So if this rule works then im assuming https inspection (we will be using a different solution for https inspection) need not be enabled ?&lt;/P&gt;&lt;P&gt;So&amp;nbsp; yeah bottom-line is i need to make the ems2.swims.faa.gov rule to work whenever the ip changes dynamically.&lt;/P&gt;&lt;P&gt;Update : Testing has been done and it looks like that url (*.ems2.swims.faa.gov) also doesnt work.&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 19:34:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117943#M21947</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-07T19:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117975#M21953</link>
      <description>&lt;P&gt;What does the log show when you filter for this destination? Does filtering for blade "url filtering" show you anything for this at all? Based on the screenshot, looks correct to me.&lt;/P&gt;</description>
      <pubDate>Sat, 08 May 2021 21:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117975#M21953</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-08T21:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117976#M21954</link>
      <description>&lt;P&gt;The logs do not show unlike the logs that are showing up for the microsoft rule that I posted.&lt;/P&gt;</description>
      <pubDate>Sat, 08 May 2021 21:30:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117976#M21954</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-08T21:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117977#M21955</link>
      <description>&lt;P&gt;I believe you are correct in this case https inspection might not be needed, but maybe someone else can confirm 100%. Well, if that same rule is hit, then we know rule is indeed working...can you please tell us what are exact FQDNs you are having issues with? I can try in my lab.&lt;/P&gt;</description>
      <pubDate>Sat, 08 May 2021 21:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/117977#M21955</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-08T21:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118092#M21963</link>
      <description>&lt;P&gt;These are the fqdns (and they do not work) that i tried:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ems2.swims.faa.gov&lt;/LI&gt;&lt;LI&gt;*.ems2.swims.faa.gov&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The user is trying to hit the url "ems2.swims.faa.gov" on a specific port. This url has a dynamic ip that changes every few weeks or so that is why i need to make it work.&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 16:21:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118092#M21963</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-10T16:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118148#M21977</link>
      <description>&lt;P&gt;You always talk about "URL". Are you sure you are using HTTP(S) here?&lt;/P&gt;
&lt;P&gt;I'm asking this, because you are using a Custom Application/Site Object with URL List definition and this only works for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;HTTP traffic over tcp ports included in "Web Browsing" object (see URL Filtering blade settings) -&amp;gt; HTTP Header is parsed&lt;/LI&gt;
&lt;LI&gt;HTTPS traffic over tcp ports included in "Web Browsing" object (see URL Filtering blade settings) AND ((HTTPS Inspection blade is used and this traffic is indeed inspected -&amp;gt; HTTP Header is parsed) OR (HTTPS Inspection Lite feature of URL Filtering Blade is used AND server certificate is trusted by CP gateway (see Trusted CA list in CP database) -&amp;gt; TLS handshake is parsed))&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When using Internet in the destination column, you have to make sure that the ip address(es) behind this FQDN is indeed Internet from perspective of this gateways topology.&lt;/P&gt;
&lt;P&gt;Also, please take care of the service field of your rule. In your first screenshot, you have three objects in the service field:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;your Custom Application/Site Object&lt;/LI&gt;
&lt;LI&gt;a TCP object named TCP-55443&lt;/LI&gt;
&lt;LI&gt;a ICMP object&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These objects are combined as OR-conjunction. So your rule currently allows TCP-55443 and ICMP to everything which matches Internet. I'm not sure, this is what you want.&lt;/P&gt;
&lt;P&gt;Last but not least:&lt;/P&gt;
&lt;P&gt;Regarding your &lt;U&gt;specific&lt;/U&gt; requirement:&lt;/P&gt;
&lt;P&gt;Why you do you not skip URL-Filtering blade (and its Custom Application/Site Objects) here and just use a FQDN network object instead of Internet in the destination field? This is enforced by firewall blade only. Just make sure you keep the FQDN checkbox ticked. &lt;A href="https://community.checkpoint.com/t5/Management/Domain-Objects-FQDN-An-Unofficial-ATRG/td-p/40789" target="_self"&gt;Since R80.20, this feature is really usable&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 12:49:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118148#M21977</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-05-11T12:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118189#M21989</link>
      <description>&lt;P&gt;ok i will try it out and will update here.&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 20:12:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118189#M21989</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-11T20:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118205#M21992</link>
      <description>&lt;P&gt;Why not try-it like we do with cases like this (as it was recommended also by others).&lt;BR /&gt;We define the&amp;nbsp;&lt;SPAN&gt;.ems2.swims.faa.gov as an FQDN object (will replace the Internet destination in you initial rule)&lt;BR /&gt;Then we remove the URL object and leave only the required special TCP port - ICMP would not be needed as ICMP is allowed by default through CKP Firewall .&lt;BR /&gt;&lt;BR /&gt;That will solve the problem with IP change on servers where the&amp;nbsp;ems2.swims.faa.gov is hosted, and allow access to that particular port you require.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 06:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118205#M21992</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2021-05-12T06:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118284#M22005</link>
      <description>&lt;P&gt;ok i did as you suggested, this is how the rule looks:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inkedfqdn_LI.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11678i47B84DD1CBC171D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Inkedfqdn_LI.jpg" alt="Inkedfqdn_LI.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the fqdn box is checked on that object.&lt;/P&gt;&lt;P&gt;Now i&amp;nbsp; need to find a way to test it out and if its working will update here thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 17:56:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118284#M22005</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-12T17:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118289#M22006</link>
      <description>&lt;P&gt;By the way does the "FQDN" box need to be checked?&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 18:16:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118289#M22006</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-12T18:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118360#M22022</link>
      <description>&lt;P&gt;Yes, as I said in my previous post, the "FQDN" checkbox absolutly needs to be checked. Please read the thread I linked in my previous post to understand why.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 06:37:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118360#M22022</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-05-14T06:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118834#M22128</link>
      <description>&lt;P&gt;So looks like the rule didnt work, the ip changed dynamically again recently and today the user complained that its not working again, is the rule correct? it does not require the url filtering blade to function right?&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 16:21:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/118834#M22128</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-05-19T16:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: custom url query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/120003#M22300</link>
      <description>&lt;P&gt;It should work. URL Filtering blade is not needed for domain objects, these are handled by firewall blade.&lt;/P&gt;
&lt;P&gt;Are you sure your gateway can do correct name resolution for that domain?&lt;/P&gt;
&lt;P&gt;You can debug it on expert shell on gateway.&lt;/P&gt;
&lt;P&gt;Here an example for registry-1.docker.io, created as FQDN object .registry-1.docker.io&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;[Expert@gateway:0]# dig registry-1.docker.io

; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.3.6-P1-RedHat-9.3.6-25.P1.11.cp994000013 &amp;lt;&amp;lt;&amp;gt;&amp;gt; registry-1.docker.io
;; global options:  printcmd
;; Got answer:
;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 39231
;; flags: qr rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 4, ADDITIONAL: 1

;; QUESTION SECTION:
;registry-1.docker.io.          IN      A

;; ANSWER SECTION:
registry-1.docker.io.   9       IN      A       34.197.211.151
registry-1.docker.io.   9       IN      A       107.23.149.57
registry-1.docker.io.   9       IN      A       54.85.56.253
registry-1.docker.io.   9       IN      A       35.153.88.109
registry-1.docker.io.   9       IN      A       3.224.96.239
registry-1.docker.io.   9       IN      A       3.229.227.53
registry-1.docker.io.   9       IN      A       18.214.230.110
registry-1.docker.io.   9       IN      A       34.238.187.50

;; AUTHORITY SECTION:
docker.io.              30290   IN      NS      ns-1827.awsdns-36.co.uk.
docker.io.              30290   IN      NS      ns-1168.awsdns-18.org.
docker.io.              30290   IN      NS      ns-421.awsdns-52.com.
docker.io.              30290   IN      NS      ns-513.awsdns-00.net.

;; ADDITIONAL SECTION:
ns-421.awsdns-52.com.   112798  IN      A       205.251.193.165

;; Query time: 3 msec
;; SERVER: 192.168.a.b#53(192.168.a.b
;; WHEN: Tue Jun  1 07:30:21 2021
;; MSG SIZE  rcvd: 322

[Expert@gateway:0]# domains_tool -d registry-1.docker.io
Domain is not attached to any IP address

Wait for the next chunk...

Domain is not attached to any IP address

Wait for the next chunk...

Domain is not attached to any IP address

Wait for the next chunk...

---------------------------------------------------------------------------------------------------
| Given Domain name:  registry-1.docker.io  FQDN: yes                                             |
---------------------------------------------------------------------------------------------------
| IP address                                                                         | sub-domain |
---------------------------------------------------------------------------------------------------
| 34.231.251.252                                                                     |     no     |
| 54.161.109.204                                                                     |     no     |
| 54.152.28.6                                                                        |     no     |
---------------------------------------------------------------------------------------------------
Total of 3 IP addresses found


Wait for the next chunk...

---------------------------------------------------------------------------------------------------
| Given Domain name:  registry-1.docker.io  FQDN: yes                                             |
---------------------------------------------------------------------------------------------------
| IP address                                                                         | sub-domain |
---------------------------------------------------------------------------------------------------
| 52.55.168.20                                                                       |     no     |
| 54.85.56.253                                                                       |     no     |
---------------------------------------------------------------------------------------------------
Total of 2 IP addresses found


Wait for the next chunk...

---------------------------------------------------------------------------------------------------
| Given Domain name:  registry-1.docker.io  FQDN: yes                                             |
---------------------------------------------------------------------------------------------------
| IP address                                                                         | sub-domain |
---------------------------------------------------------------------------------------------------
| 3.209.182.229                                                                      |     no     |
| 3.229.227.53                                                                       |     no     |
| 35.175.91.243                                                                      |     no     |
| 35.153.88.109                                                                      |     no     |
---------------------------------------------------------------------------------------------------
Total of 4 IP addresses found


Wait for the next chunk...

---------------------------------------------------------------------------------------------------
| Given Domain name:  registry-1.docker.io  FQDN: yes                                             |
---------------------------------------------------------------------------------------------------
| IP address                                                                         | sub-domain |
---------------------------------------------------------------------------------------------------
| 52.72.232.213                                                                      |     no     |
| 3.220.36.210                                                                       |     no     |
---------------------------------------------------------------------------------------------------
Total of 2 IP addresses found


Wait for the next chunk...

---------------------------------------------------------------------------------------------------
| Given Domain name:  registry-1.docker.io  FQDN: yes                                             |
---------------------------------------------------------------------------------------------------
| IP address                                                                         | sub-domain |
---------------------------------------------------------------------------------------------------
| 54.236.165.68                                                                      |     no     |
| 3.224.96.239                                                                       |     no     |
| 35.169.249.115                                                                     |     no     |
| 107.23.149.57                                                                      |     no     |
| 18.214.230.110                                                                     |     no     |
| 34.197.211.151                                                                     |     no     |
---------------------------------------------------------------------------------------------------
Total of 6 IP addresses found


Wait for the next chunk...

---------------------------------------------------------------------------------------------------
| Given Domain name:  registry-1.docker.io  FQDN: yes                                             |
---------------------------------------------------------------------------------------------------
| IP address                                                                         | sub-domain |
---------------------------------------------------------------------------------------------------
| 34.238.187.50                                                                      |     no     |
---------------------------------------------------------------------------------------------------
Total of 1 IP addresses found


Wait for the next chunk...

Domain is not attached to any IP address

Wait for the next chunk...

Domain is not attached to any IP address
[Expert@gateway:0]# &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 05:34:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/custom-url-query/m-p/120003#M22300</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-01T05:34:51Z</dc:date>
    </item>
  </channel>
</rss>

