<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network Objects and DNS. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/220963#M36814</link>
    <description>&lt;P&gt;Hello and Good afternoon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently managing a cluster of two 6000 series Appliances and a number of 1575 Gateways that are connected to the main 6000 appliances with an IPsec VPN.&lt;/P&gt;&lt;P&gt;At the moment the remote locations are reliant on the DHCP and DNS servers in our headquarters. We want to change this so that the remote office is independent when the IPsec VPN fails. This means&amp;nbsp;&lt;SPAN&gt;DHCP must be done on the remote firewall for each VLAN and something must be done about DNS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Moving DHCP to the Firewall is not a problem. divide the scopes between the two firewalls and go! Works...&lt;/P&gt;&lt;P&gt;At the moment we have one location where we have a delegated DNS instance in our central DNS servers. We defined the DNS suffix in the firewall as location-1.company.local.&lt;/P&gt;&lt;P&gt;Only when I register an Access Point on the locations firewall as a network object, can I ping it from headquarters. What I want to reach is that devices will register themselves in the DNS on the firewall so they become network objects. One can imagine that registering devices manually is not a job anyone would want to do. All those laptops......Also when I travel to that location I would have to register my device in the network objects db so I can be pinged/found by my hostname. This is not done....&lt;BR /&gt;&lt;BR /&gt;The question is, how do I make this work automatically? How do I make sure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Devices get an IP from their local FW? ---done---&lt;/LI&gt;&lt;LI&gt;Devices register themselves in the firewalls DNS database?&lt;/LI&gt;&lt;LI&gt;When the IPsec fails, the DNS requests should be forwarded to a public DNS server by the firewall.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;so far my explanation....If there are questions let me know. My first message here and not super experienced with CheckPoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jul 2024 13:35:32 GMT</pubDate>
    <dc:creator>demirdag</dc:creator>
    <dc:date>2024-07-16T13:35:32Z</dc:date>
    <item>
      <title>Network Objects and DNS.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/220963#M36814</link>
      <description>&lt;P&gt;Hello and Good afternoon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently managing a cluster of two 6000 series Appliances and a number of 1575 Gateways that are connected to the main 6000 appliances with an IPsec VPN.&lt;/P&gt;&lt;P&gt;At the moment the remote locations are reliant on the DHCP and DNS servers in our headquarters. We want to change this so that the remote office is independent when the IPsec VPN fails. This means&amp;nbsp;&lt;SPAN&gt;DHCP must be done on the remote firewall for each VLAN and something must be done about DNS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Moving DHCP to the Firewall is not a problem. divide the scopes between the two firewalls and go! Works...&lt;/P&gt;&lt;P&gt;At the moment we have one location where we have a delegated DNS instance in our central DNS servers. We defined the DNS suffix in the firewall as location-1.company.local.&lt;/P&gt;&lt;P&gt;Only when I register an Access Point on the locations firewall as a network object, can I ping it from headquarters. What I want to reach is that devices will register themselves in the DNS on the firewall so they become network objects. One can imagine that registering devices manually is not a job anyone would want to do. All those laptops......Also when I travel to that location I would have to register my device in the network objects db so I can be pinged/found by my hostname. This is not done....&lt;BR /&gt;&lt;BR /&gt;The question is, how do I make this work automatically? How do I make sure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Devices get an IP from their local FW? ---done---&lt;/LI&gt;&lt;LI&gt;Devices register themselves in the firewalls DNS database?&lt;/LI&gt;&lt;LI&gt;When the IPsec fails, the DNS requests should be forwarded to a public DNS server by the firewall.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;so far my explanation....If there are questions let me know. My first message here and not super experienced with CheckPoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 13:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/220963#M36814</guid>
      <dc:creator>demirdag</dc:creator>
      <dc:date>2024-07-16T13:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Network Objects and DNS.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/221287#M36900</link>
      <description>&lt;P&gt;Just to clarify: you want a device to register itself to the DNS server inside the 1575?&lt;BR /&gt;This may be possible by hacking the &lt;A href="https://thekelleys.org.uk/dnsmasq/doc.html" target="_blank"&gt;dnsmasq&lt;/A&gt; configuration, with the configuration file in /pfrm2.0/etc/dnsmasq.conf&lt;BR /&gt;"When IPsec fails" the only way you can achieve that is by specifying a public DNS as a backup, as far as I know.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 19:05:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/221287#M36900</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-18T19:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Network Objects and DNS.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/223138#M37170</link>
      <description>&lt;P&gt;Yes, that is what we would like to accomplish. I have been looking for dnsmasq configuration options and found some examples. Looking into it....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 08:31:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Network-Objects-and-DNS/m-p/223138#M37170</guid>
      <dc:creator>demirdag</dc:creator>
      <dc:date>2024-08-09T08:31:59Z</dc:date>
    </item>
  </channel>
</rss>

