<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Domain objects in R80.10 spamming DNS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19786#M3673</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wondering if anyone else has noticed if you are using domain objects (new type)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed high amount of &lt;STRONG&gt;Block / Alert&lt;/STRONG&gt; logs on the gateway complaining it was not able to resolve DNS even though DNS is responding OK.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68898_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run tcpdump I noticed that firewall sends DNS requests for &lt;STRONG&gt;each&lt;/STRONG&gt; domain object in big batches (multiple requests for the same name within 100ms). So there are hundreds of DNS requests spat out every 30 secs for 20 domain objects so I'm not surprised if some are not answered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68897_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not raised SR yet - just wondering if it's "known" issue? We are on take 121.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is one SK that matches symptoms but that should have been fixed in take 42&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120558" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120558"&gt;"Firewall - Domain resolving error. Check DNS configuration on the gateway." log for blocked HTTP traffic although relev…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Aug 2018 09:03:32 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2018-08-16T09:03:32Z</dc:date>
    <item>
      <title>Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19786#M3673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wondering if anyone else has noticed if you are using domain objects (new type)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed high amount of &lt;STRONG&gt;Block / Alert&lt;/STRONG&gt; logs on the gateway complaining it was not able to resolve DNS even though DNS is responding OK.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68898_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run tcpdump I noticed that firewall sends DNS requests for &lt;STRONG&gt;each&lt;/STRONG&gt; domain object in big batches (multiple requests for the same name within 100ms). So there are hundreds of DNS requests spat out every 30 secs for 20 domain objects so I'm not surprised if some are not answered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68897_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not raised SR yet - just wondering if it's "known" issue? We are on take 121.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is one SK that matches symptoms but that should have been fixed in take 42&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120558" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120558"&gt;"Firewall - Domain resolving error. Check DNS configuration on the gateway." log for blocked HTTP traffic although relev…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19786#M3673</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-08-16T09:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19787#M3674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, it seems RAD cache is not okay. Please do open a support ticket for proper diagnostics&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:40:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19787#M3674</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-16T09:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19788#M3675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using&amp;nbsp;None-FQDN mode (sk120633) ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19788#M3675</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-16T09:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19789#M3676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's the R80.10 FQDN type objects. Using old makes no sense &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 10:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19789#M3676</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-08-16T10:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19790#M3677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I second that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 10:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19790#M3677</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-16T10:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19791#M3678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SR is still under investigation but someone else is bored, you may check if your gateway is sending malformed truncated DNS requests using TCP - has all domain objects included multiple times but most importantly packet format is wrong. Our DNS just replies as malformed packet, no results. Seems to match Blocked traffic in logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68952_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 12:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19791#M3678</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-08-17T12:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19792#M3679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a known issue, solved in R80.10 JHF T142.&lt;/P&gt;&lt;P&gt;It will happen when&amp;nbsp;using&amp;nbsp;large amount of domain&amp;nbsp;objects in policy.&lt;/P&gt;&lt;P&gt;Please contact support (&amp;amp; CFG) if you need the fix on top of earlier JHF take.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Meital&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 13:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19792#M3679</guid>
      <dc:creator>Meital_Natanson</dc:creator>
      <dc:date>2018-08-30T13:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19793#M3680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks heaps Meital! Strangely enough case engineer just asked me for more debugs and logs instead of suggesting this...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 13:13:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19793#M3680</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-08-30T13:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19794#M3681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Haha - I didn't realise that you were from R&amp;amp;D .. Just had a call from case engineer. All good - we'll try one cluster in next couple of days! Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 13:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19794#M3681</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-08-30T13:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in R80.10 spamming DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19795#M3682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One last update - finally we rolled out take 142 last night in production: 2 VSX clusters and one non-VSX. All looking great so far, all block logs gone!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2018 10:58:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-R80-10-spamming-DNS/m-p/19795#M3682</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-09-05T10:58:25Z</dc:date>
    </item>
  </channel>
</rss>

