<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implied rule for DNS  Accept domain name over UDP queries. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136555#M24415</link>
    <description>&lt;P&gt;1. Implied rule for DNS is looking as "ANY--ANY--domain-UDP--Accept", so if you choose "First" option for that, all DNS traffic will go through an implied rule.&lt;/P&gt;
&lt;P&gt;2. If you choose "Before Last", make sure none on explicit rules drops DNS, just in case. In other words, check drop rules in the policy, to answer your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, it DNS through implied rules is not enable by default, as you may need to control this traffic properly, with tighter rules.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Dec 2021 14:58:33 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-12-16T14:58:33Z</dc:date>
    <item>
      <title>Implied rule for DNS  Accept domain name over UDP queries.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136548#M24414</link>
      <description>&lt;P&gt;In my scenario we have enabled implied rule for DNS "Accept domain name over UDP queries." as before last in Global properties.&lt;/P&gt;&lt;P&gt;In logs i can see lot of company machines to external DNS servers (hitting on implied rule) my task is disable option "Accept domain name over UDP queries." from&amp;nbsp;Global properties.&lt;/P&gt;&lt;P&gt;Question as :&lt;/P&gt;&lt;P&gt;1 I already have my internal DNS specified in explicit rule. but still few user machines hitting external DNS server hitting through implied rule. is there any specific reason of this behavior ?&lt;/P&gt;&lt;P&gt;2 In above scenario if i directly disable option "Accept domain name over UDP queries. as before last" will&amp;nbsp; it have any impact ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 14:30:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136548#M24414</guid>
      <dc:creator>kaustubh</dc:creator>
      <dc:date>2021-12-16T14:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule for DNS  Accept domain name over UDP queries.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136555#M24415</link>
      <description>&lt;P&gt;1. Implied rule for DNS is looking as "ANY--ANY--domain-UDP--Accept", so if you choose "First" option for that, all DNS traffic will go through an implied rule.&lt;/P&gt;
&lt;P&gt;2. If you choose "Before Last", make sure none on explicit rules drops DNS, just in case. In other words, check drop rules in the policy, to answer your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, it DNS through implied rules is not enable by default, as you may need to control this traffic properly, with tighter rules.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 14:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136555#M24415</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-16T14:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule for DNS  Accept domain name over UDP queries.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136970#M24459</link>
      <description>&lt;P&gt;Hello Val,&lt;/P&gt;&lt;P&gt;Sorry for delay.&lt;/P&gt;&lt;P&gt;current implied rule for "queries over UDP" set as "&lt;SPAN&gt;Before Last".. but i have defined my internal DNS server as well in explicit rule.. but still i can see random ip's are trying to connect to external DNS servers..( my task is to disable option "queries over UDP".i have fear if i directly disable it then legitimate traffic may get break.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what could be the possible reason of that ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 10:33:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136970#M24459</guid>
      <dc:creator>kaustubh</dc:creator>
      <dc:date>2021-12-22T10:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule for DNS  Accept domain name over UDP queries.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136971#M24460</link>
      <description>&lt;P&gt;What are the random IPs and how is their DNS settings configured?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 10:39:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136971#M24460</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-12-22T10:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule for DNS  Accept domain name over UDP queries.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136972#M24461</link>
      <description>&lt;P&gt;I checked few windows machines/fw's &amp;amp; their DNS servers in N/W adaptor is my internal DNS server only.. but still logs showing these devices are trying to connect nearest ISP's DNS servers.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 10:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rule-for-DNS-Accept-domain-name-over-UDP-queries/m-p/136972#M24461</guid>
      <dc:creator>kaustubh</dc:creator>
      <dc:date>2021-12-22T10:42:32Z</dc:date>
    </item>
  </channel>
</rss>

