<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS trap in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/226033#M37715</link>
    <description>&lt;P&gt;Should I allow traffic to the bogus trap IP in security policy rule?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2024 18:37:09 GMT</pubDate>
    <dc:creator>Emil_T</dc:creator>
    <dc:date>2024-09-09T18:37:09Z</dc:date>
    <item>
      <title>DNS trap</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/185127#M30848</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello support,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is the default address of DNS trap 62.0.58.94 and not something else, what is the significance of this choice? When DNS trap is triggered, does DNS traffic go to 62.0.58.94? Or did he simply replace the destination DNS address with 62.0.58.94&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Qiuyao Dai&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 03:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/185127#M30848</guid>
      <dc:creator>Qiuyao</dc:creator>
      <dc:date>2023-06-29T03:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/185187#M30860</link>
      <description>&lt;P&gt;The significance of the choice is simple: Check Point owns this IP address.&lt;BR /&gt;You can verify this through WHOIS records.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we detect a DNS lookup for a domain that is malicious, we replace the results of that query with the configured IP DNS Trap address.&lt;BR /&gt;The idea being: instead of connecting to the malicious host, the client will connect to the DNS Trap address, which should ultimately be harmless to the end user.&lt;/P&gt;
&lt;P&gt;To the best of my knowledge, there is no host assigned to&amp;nbsp;&lt;SPAN&gt;62.0.58.94.&lt;BR /&gt;Which means all traffic sent to this IP will fail and result in no harm to and end user.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 16:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/185187#M30860</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-29T16:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/185244#M30881</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For more info please refer:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk74060" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk74060: Anti-Virus&amp;nbsp;&lt;STRONG&gt;Malware&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;DNS&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Trap&lt;/STRONG&gt;&amp;nbsp;feature&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 00:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/185244#M30881</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-30T00:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/226033#M37715</link>
      <description>&lt;P&gt;Should I allow traffic to the bogus trap IP in security policy rule?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 18:37:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/226033#M37715</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2024-09-09T18:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS trap</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/226064#M37725</link>
      <description>&lt;P&gt;Don't believe it is necessary.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 20:14:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-trap/m-p/226064#M37725</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-09T20:14:57Z</dc:date>
    </item>
  </channel>
</rss>

