<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS rewriting Hack in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232272#M38814</link>
    <description>&lt;P&gt;Good point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Nov 2024 23:36:46 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-11-10T23:36:46Z</dc:date>
    <item>
      <title>DNS rewriting Hack</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232072#M38788</link>
      <description>&lt;P&gt;I have found an interesting way to rewrite DNS requests to other IP addresses.&lt;BR /&gt;This makes it possible to use the internal private addresses on the internal DNS server for the DNS requests. &lt;BR /&gt;External DNS queries that are requested via the Internet can be rewritten to official addresses on the firewall.&lt;BR /&gt;The ISP function can be used as a hack for this purpose.&lt;/P&gt;
&lt;P&gt;If you activate and configure ISP Redundancy on the gateway, you have the option of rewriting DNS queries. This can be used to rewrite regular DNS queries to other IP addresses.&lt;BR /&gt;&lt;BR /&gt;Example configuration:&lt;/P&gt;
&lt;P&gt;1) Enable ISP on the gateway&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS1_57h543.jpg" style="width: 564px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28408iFFFC1FAF07E15CA0/image-size/large?v=v2&amp;amp;px=999" role="button" title="DNS1_57h543.jpg" alt="DNS1_57h543.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;2) Now select the “Primary/Backup” redundancy mode (see picture 1)&lt;BR /&gt;&lt;BR /&gt;3) Now create an ISP link (that corresponds to your external interface in the direction to the Internet in my example “external_interface”.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS2_345njk3k4.jpg" style="width: 495px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28409i76EC3BDBACE0F773/image-size/large?v=v2&amp;amp;px=999" role="button" title="DNS2_345njk3k4.jpg" alt="DNS2_345njk3k4.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;4) Unfortunately, two interfaces must be defined, so you have to work with a placeholder interface for ISP2 link. Then create a link that only functions as a placeholder in my example “not_used”. Fictitious IP addresses can be used for the interface.&lt;/P&gt;
&lt;P&gt;5) Now enabling “DNS Proxy”&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS2B_64hjh423.png" style="width: 417px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28410i74BE6882F0DBD9B4/image-dimensions/417x47?v=v2" width="417" height="47" role="button" title="DNS2B_64hjh423.png" alt="DNS2B_64hjh423.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;6) In the next step, you can enter the DNS settings that you want to rewrite (red).&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS3_345hj345.png" style="width: 907px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28411i9913B47A13E3119E/image-size/large?v=v2&amp;amp;px=999" role="button" title="DNS3_345hj345.png" alt="DNS3_345hj345.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;You can enter any address for the second ISP backup link (blue), as this is not used in my example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 09:25:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232072#M38788</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2024-11-08T09:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: DNS rewriting Hack</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232083#M38790</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;not sure if you could call it a "hack" ... it just the way it works i would say ...&lt;BR /&gt;overwrite everything with your manual configuration&lt;BR /&gt;maybe a dirty way to make split DNS when connecting via Client VPN. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2024 10:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232083#M38790</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2024-11-08T10:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: DNS rewriting Hack</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232227#M38813</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24246"&gt;@Thomas_Eichelbu&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Hack or no hack. &lt;BR /&gt;&lt;BR /&gt;Had used ISP in a customer project to do this. &lt;BR /&gt;It is the only way I know of to rewrite DNS requests on a gateway&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;. &lt;BR /&gt;&lt;BR /&gt;It is a pity that there is no DNS proxy that can be used to rewrite DNS queries. It was a feature request of me years ago.&lt;BR /&gt;ISP primary is not designed to rewrite DNS requests, but it can be used to do so, even if only one internet service provider is used.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 16:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232227#M38813</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2024-11-09T16:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: DNS rewriting Hack</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232272#M38814</link>
      <description>&lt;P&gt;Good point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2024 23:36:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232272#M38814</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-10T23:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS rewriting Hack</title>
      <link>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232376#M38829</link>
      <description>&lt;P&gt;Someone must have heard you (and others) as it's integrated into R82:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Hosts-and-DNS-DNS-Proxy-Forwarding-Domains.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG/Hosts-and-DNS-DNS-Proxy-Forwarding-Domains.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The funny thing is that&amp;nbsp;&lt;A href="https://phoneboy.org/2014/09/02/fun-with-check-point-dynamic-ip-gateways-in-r77-dot-20-with-gaia/" target="_self"&gt;dnsmasq has been installed on Gaia since at least R77.20&lt;/A&gt;&amp;nbsp;though it was disabled.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2024 23:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/DNS-rewriting-Hack/m-p/232376#M38829</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-11T23:02:05Z</dc:date>
    </item>
  </channel>
</rss>

