<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need a little help please in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20718#M3815</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We’re running v 77.30 and my firewall guys are telling me that we can’t use a DNS service without a proxy. However we have some calls that can’t be proxied. They are currently hard coding the IP addresses for those partners – but as you know, IPs change and sure enough, it broke at 12am Sat morning and was down all weekend. There has to be a better way to resolve domains than hard coding IPs. Do you have any ideas or suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 May 2018 14:55:50 GMT</pubDate>
    <dc:creator>Jen_Brown</dc:creator>
    <dc:date>2018-05-02T14:55:50Z</dc:date>
    <item>
      <title>Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20718#M3815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We’re running v 77.30 and my firewall guys are telling me that we can’t use a DNS service without a proxy. However we have some calls that can’t be proxied. They are currently hard coding the IP addresses for those partners – but as you know, IPs change and sure enough, it broke at 12am Sat morning and was down all weekend. There has to be a better way to resolve domains than hard coding IPs. Do you have any ideas or suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 14:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20718#M3815</guid>
      <dc:creator>Jen_Brown</dc:creator>
      <dc:date>2018-05-02T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20719#M3816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any chance the IP address shifts within a specific range? There were times where we just created a network object or IP range for access to a vendor.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes I've been able to get a list of IP ranges from the vendor and make a group based on their list.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess none of this helps you if the host resolves to a CDN network or AWS, though.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 20:22:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20719#M3816</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-05-02T20:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20720#M3817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's certainly possible for organizations to set up DNS in such a way that an internal DNS server is only able to resolve internal (non-Internet) addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If internal resources want to reach the Internet in this situation, they are forced to use a proxy to do so.&lt;/P&gt;&lt;P&gt;This is usually for HTTP/HTTPS, and the proxy server generally has access to DNS servers capable of resolving addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like you have some application that can't use this sort of proxy and has been given direct access to the Internet.&lt;/P&gt;&lt;P&gt;However, you need to know what IP address&amp;nbsp;the connection uses because you do not have access to Internet DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the above has anything to do with Check Point, or any specific security gateway vendor for that matter.&lt;/P&gt;&lt;P&gt;It's a function of how the environment is set up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you solve the DNS problem on the client side,&amp;nbsp;there's the matter of allowing access to that IP (whatever it is).&lt;/P&gt;&lt;P&gt;That would be where Check Point&amp;nbsp;is relevant to the discussion.&lt;/P&gt;&lt;P&gt;If the relevant parties want to have a discussion about that portion, they can do so here, through our TAC, Check Point account team, etc.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 20:39:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20720#M3817</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-02T20:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20721#M3818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah it resolves to AWS. What we need is a fw rule to a non-static ip or dns entity; Or a fw rule to a cloud hosted server. Ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 20:42:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20721#M3818</guid>
      <dc:creator>Jen_Brown</dc:creator>
      <dc:date>2018-05-02T20:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20722#M3819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out this &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk41632"&gt;sk&lt;/A&gt; article &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk41632"&gt;"Best Practices - Working with Domain Objects (Pre R80.10)"&lt;/A&gt;&amp;nbsp;as far as I know, these are the definitive options for pre-R80.10 Gateways!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you go the route of creating a domain object, try to put it as close to the bottom of the policy as possible!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 20:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20722#M3819</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-05-02T20:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20723#M3820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is much easier in R80.10 where you can use an FDQN Domain object in the access policy.&lt;/P&gt;&lt;P&gt;In earlier releases like R77.30, see my answer in this thread:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/6249"&gt;Dynamic Objects (URL)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 20:51:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20723#M3820</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-02T20:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Need a little help please</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20724#M3821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I knew there had to be a way to do this. Thank you so much! I'm going to pass this along to my guys.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You just made my day - thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 22:05:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Need-a-little-help-please/m-p/20724#M3821</guid>
      <dc:creator>Jen_Brown</dc:creator>
      <dc:date>2018-05-02T22:05:42Z</dc:date>
    </item>
  </channel>
</rss>

