<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN destination natively supported R80+? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163659#M27352</link>
    <description>&lt;P&gt;We're using Domain Objects since couple of years without a problem (we have ~500 objects). Just pay attention that in some cases (like 1 in 100 or 1000) there might be a situation that your client would resolve the domain to IP address 1.2.3.4 while the CheckPoint GW would resolve that same domain to 1.3.4.2 IP address . To be honest, we never encountered that, or at leas I was not aware in those couple of years we're using it....&lt;/P&gt;
&lt;P&gt;So in order not to face that, make sure that the DNS servers used by your clients, will be same as your CheckPoint Gateways, like some internal DNS servers....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One other thing, the object definition has an option to perform reverse DNS in order to assure that the IP resolves to the domain and vice-versa, still with cloud these days, the revers does not match.... so pay attention to that part.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2022 07:00:38 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-11-30T07:00:38Z</dc:date>
    <item>
      <title>FQDN destination natively supported R80+?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163624#M27333</link>
      <description>&lt;P&gt;We have a number of outbound Internet rules that we have to update regularly due to the destination IP changing:&lt;/P&gt;&lt;P&gt;Ie: URL thiswebsite.com was 1.2.3.4 and then the remote site IP changed to 7.8.9.10&lt;/P&gt;&lt;P&gt;Which means we have go update the thiswebsite.com firewall object that we have.&lt;/P&gt;&lt;P&gt;Is URL/FQDN natively supported/permitted without a license in R80+?&lt;/P&gt;&lt;P&gt;meaning - I can create a URL object call thiswebsite.com and when the IP changes at the remote side I have no need to update my rule(s)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 23:07:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163624#M27333</guid>
      <dc:creator>JaySon_2021</dc:creator>
      <dc:date>2022-11-29T23:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN destination natively supported R80+?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163645#M27348</link>
      <description>&lt;P&gt;Yes, they are called Domain objects.&lt;BR /&gt;See&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120633&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120633&amp;amp;partition=Basic&amp;amp;product=Quantum&lt;/A&gt;&lt;BR /&gt;Domain Objects are supported with the basic firewall license.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 02:30:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163645#M27348</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-30T02:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN destination natively supported R80+?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163650#M27351</link>
      <description>&lt;P&gt;Phoneboy said it right, you just need basic license to use domain objects, no need for anything special.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 02:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163650#M27351</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-30T02:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN destination natively supported R80+?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163659#M27352</link>
      <description>&lt;P&gt;We're using Domain Objects since couple of years without a problem (we have ~500 objects). Just pay attention that in some cases (like 1 in 100 or 1000) there might be a situation that your client would resolve the domain to IP address 1.2.3.4 while the CheckPoint GW would resolve that same domain to 1.3.4.2 IP address . To be honest, we never encountered that, or at leas I was not aware in those couple of years we're using it....&lt;/P&gt;
&lt;P&gt;So in order not to face that, make sure that the DNS servers used by your clients, will be same as your CheckPoint Gateways, like some internal DNS servers....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One other thing, the object definition has an option to perform reverse DNS in order to assure that the IP resolves to the domain and vice-versa, still with cloud these days, the revers does not match.... so pay attention to that part.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 07:00:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163659#M27352</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-11-30T07:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN destination natively supported R80+?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163765#M27371</link>
      <description>&lt;P&gt;Even in the 90s, Reverse DNS didn't always match up very well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 18:37:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FQDN-destination-natively-supported-R80/m-p/163765#M27371</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-30T18:37:29Z</dc:date>
    </item>
  </channel>
</rss>

