<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS problems possibly due to firewall issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134982#M24159</link>
    <description>&lt;P&gt;Yes we have VPN&lt;/P&gt;</description>
    <pubDate>Fri, 26 Nov 2021 12:52:22 GMT</pubDate>
    <dc:creator>SG22</dc:creator>
    <dc:date>2021-11-26T12:52:22Z</dc:date>
    <item>
      <title>DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134899#M24144</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;&lt;BR /&gt;We have 3 DNS servers, one in my office and 2 in another location.&amp;nbsp;Firewall is doing DHCP, in Firewall configuration DNS in mu location is primary and DNSes in another location are secondary and&amp;nbsp;tertiary.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently we started to experience problems with DNS. It takes forever to resolve queries. It takes a minute to open webpage, it takes 2-5 minutes to log in to workstation. &lt;STRONG&gt;Nslookup doesn't work.&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;I temporarily changed DNS on my PC to google DNS, and it started to work. So I thought it is DNS problem. First I changed primary DNS on my workstation to be one from another location, but nothing changed. Then I changed Forwarders in DNS settings, cleared cache, but still same problem.&lt;BR /&gt;&lt;BR /&gt;So I rebooted firewall and after firewall reboot, everything started to work without any issues for a couple of hours. After couple of hours same problem. So I rebooted firewall again, still just a temporary solution.&lt;BR /&gt;&lt;BR /&gt;In other office we have same firewall, and there everything works without issues. DNS resolves queries. But even when I put their DNS as a primary on my workstation, or any workstation in my office, we have a problem.&lt;BR /&gt;&lt;BR /&gt;Do you have an idea what can be issue? Please have in mind that I'm just junior without any firewall experience, so try to explain it to me like I'm an idiot.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 12:13:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134899#M24144</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-25T12:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134944#M24150</link>
      <description>&lt;P&gt;How do you know the FW is in fault? Any logs to prove it?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 20:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134944#M24150</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-25T20:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134945#M24151</link>
      <description>&lt;P&gt;Also, do you have a VPN between your location and the other one?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 20:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134945#M24151</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-25T20:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134947#M24153</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;is correct...I mean, I get what you described here, but its hard to draw logical conclusion that this is a firewall problem. If you reboot the firewall, great, we know it works for a bit, but still does not prove fw problem. Can you post any logs, captures when issue is happening? Try do pings on the firewall at the same time, because the response in mili seconds will give us a good idea.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 21:31:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134947#M24153</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-25T21:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134981#M24158</link>
      <description>&lt;P&gt;Well, I don't know. It is just a guess because it started to work after reboot.&lt;BR /&gt;&lt;BR /&gt;No, I don't. That is why I started the topic, I don't know where to look and what to do to exclude firewall as possible cause.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 12:52:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134981#M24158</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T12:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134982#M24159</link>
      <description>&lt;P&gt;Yes we have VPN&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 12:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134982#M24159</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T12:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134986#M24160</link>
      <description>&lt;P&gt;If you do, please check that if DNS traffic is using VPN, to communicate between DNS servers on both sites. It might be, your VPN S2S tunnel fails after two hours, and this breaks DNS. Is any other site to site communication is affected, when DNS fails?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134986#M24160</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-26T13:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134989#M24161</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/56564"&gt;@SG22&lt;/a&gt;&amp;nbsp;...thats why we are here to help you. So, lets start with basics...if you search the logs in dashboard and filter for say IP of your dns server and action drop, do you see anything when issue is happening? You can also run from fw expert mode this command -&amp;gt; fw ctl zdebug + drop | grep 53 (thats for dns port) or fw ctl zdebug + drop | grep x.x.x.x (just replace with dns server IP) and observe the results.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134989#M24161</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-26T13:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134995#M24165</link>
      <description>&lt;P&gt;No, no drops. And for fw ctl zdebug i get obsolete command. Do you know alternative command?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:55:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134995#M24165</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T13:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134997#M24167</link>
      <description>&lt;P&gt;Can you send exact debug command you ran?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:57:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134997#M24167</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-26T13:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134998#M24168</link>
      <description>&lt;P&gt;Which version of FW are you running?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:58:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134998#M24168</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-26T13:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134999#M24169</link>
      <description>&lt;P&gt;The problem is only from our side. They can reach us without issue, but we can't reach them.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:58:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/134999#M24169</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T13:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135002#M24171</link>
      <description>&lt;P&gt;So, here is what I can tell you.&lt;BR /&gt;&lt;BR /&gt;No DNS errors in Event viewer on server.&lt;BR /&gt;&lt;BR /&gt;I used DNS Query Sniffer on my workstation and on my DNS server.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On workstation: First 5 queries fail always and 6th one passes. It is always a&amp;nbsp;&lt;SPAN&gt;tertiary server that resolves queries. No matter which one I use as&amp;nbsp;tertiary.&lt;BR /&gt;&lt;BR /&gt;On the server: All queries are passing (around 150 ms for uncached ones). But also I have a problem opening web pages on DNS server.&lt;BR /&gt;&lt;BR /&gt;Ping in internal network I around 1 ms (doesn't matter if I use hostname or IP address)&lt;BR /&gt;Ping to other location is around 30 ms (I tried to ping external IP of the Firewall and a couple of servers)&lt;BR /&gt;&lt;BR /&gt;Nslookup doesn't work on workstations&lt;BR /&gt;Nslookup works on DNS server, but only if you ping site first (and it is really slow)&lt;BR /&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:11:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135002#M24171</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T14:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135003#M24172</link>
      <description>&lt;P&gt;Checkpoint 5200&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:13:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135003#M24172</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T14:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135004#M24173</link>
      <description>&lt;P&gt;Val meant software version, not model. Is it R80.30, R80,40, R81? Something else? What jumbo?&lt;/P&gt;
&lt;P&gt;Just run cpinfo -y all and send the output.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:16:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135004#M24173</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-26T14:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135005#M24174</link>
      <description>&lt;P&gt;Let me ask you this, by the way, thanks for that explanation, thats very helpful! What happens if someone connects say via CP vpn endpoint client and tries to run these tests, is result exactly the same? Because if yes, that might be something to do with optional parameters on the gateway properties for vpn. Are you using right dns servers/dns suffix in gateway settings? If you navigate to dns and hosts from web UI page, you can check it there.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:19:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135005#M24174</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-26T14:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135006#M24175</link>
      <description>&lt;P&gt;Oh sorry. I also get "Deprecated command" as a resault. But I'm pretty sure we use R80.40&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135006#M24175</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T14:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135008#M24177</link>
      <description>&lt;P&gt;Ok, message me directly. Lets do remote session, I have time today. I really want to see this behavior for myself.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135008#M24177</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-26T14:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135009#M24178</link>
      <description>&lt;P&gt;Users on endpoint client don't have any issues. DNS servers are ok, those are the one we use and suffix is ok.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135009#M24178</guid>
      <dc:creator>SG22</dc:creator>
      <dc:date>2021-11-26T14:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: DNS problems possibly due to firewall issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135014#M24181</link>
      <description>&lt;P&gt;That's appliance model. What's the SW version? Run "fw ver" command on the console&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 15:13:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-problems-possibly-due-to-firewall-issue/m-p/135014#M24181</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-26T15:13:18Z</dc:date>
    </item>
  </channel>
</rss>

