<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understanding Domain Object in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240024#M40057</link>
    <description>&lt;P&gt;Our windows defender is not connecting to the Microsoft portal, then when i run the script from Microsoft i can see the traffic to&amp;nbsp;winatp-gw-cus.microsoft.com is blocked.&lt;/P&gt;
&lt;P&gt;From the microsoft documentation there are several winatp subdomain such as :&lt;/P&gt;
&lt;P&gt;winatp-gw-aue.microsoft.com&lt;BR /&gt;winatp-gw-aus.microsoft.com&lt;BR /&gt;winatp-gw-neu.microsoft.com&lt;BR /&gt;winatp-gw-weu.microsoft.com&lt;BR /&gt;winatp-gw-neu3.microsoft.com&lt;BR /&gt;winatp-gw-weu3.microsoft.com&lt;BR /&gt;winatp-gw-uks.microsoft.com&lt;BR /&gt;winatp-gw-ukw.microsoft.com&lt;BR /&gt;winatp-gw-cus.microsoft.com&lt;BR /&gt;winatp-gw-eus.microsoft.com&lt;BR /&gt;winatp-gw-cus3.microsoft.com&lt;BR /&gt;winatp-gw-eus3.microsoft.com&lt;/P&gt;
&lt;P&gt;Then i try to make domain object .microsoft.com and the traffic still blocked.&lt;/P&gt;
&lt;P&gt;So anyone here can help me to understanding about domain object in the checkpoint? What in my mind is when we create .microsoft.com this same with *.microsoft.com and all hosts and sub domains under microsoft.com will be permitted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 02:51:08 GMT</pubDate>
    <dc:creator>handiansudianto</dc:creator>
    <dc:date>2025-01-30T02:51:08Z</dc:date>
    <item>
      <title>Understanding Domain Object</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240024#M40057</link>
      <description>&lt;P&gt;Our windows defender is not connecting to the Microsoft portal, then when i run the script from Microsoft i can see the traffic to&amp;nbsp;winatp-gw-cus.microsoft.com is blocked.&lt;/P&gt;
&lt;P&gt;From the microsoft documentation there are several winatp subdomain such as :&lt;/P&gt;
&lt;P&gt;winatp-gw-aue.microsoft.com&lt;BR /&gt;winatp-gw-aus.microsoft.com&lt;BR /&gt;winatp-gw-neu.microsoft.com&lt;BR /&gt;winatp-gw-weu.microsoft.com&lt;BR /&gt;winatp-gw-neu3.microsoft.com&lt;BR /&gt;winatp-gw-weu3.microsoft.com&lt;BR /&gt;winatp-gw-uks.microsoft.com&lt;BR /&gt;winatp-gw-ukw.microsoft.com&lt;BR /&gt;winatp-gw-cus.microsoft.com&lt;BR /&gt;winatp-gw-eus.microsoft.com&lt;BR /&gt;winatp-gw-cus3.microsoft.com&lt;BR /&gt;winatp-gw-eus3.microsoft.com&lt;/P&gt;
&lt;P&gt;Then i try to make domain object .microsoft.com and the traffic still blocked.&lt;/P&gt;
&lt;P&gt;So anyone here can help me to understanding about domain object in the checkpoint? What in my mind is when we create .microsoft.com this same with *.microsoft.com and all hosts and sub domains under microsoft.com will be permitted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 02:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240024#M40057</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2025-01-30T02:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Domain Object</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240035#M40059</link>
      <description>&lt;P&gt;Non-FDQN Domain Objects use Reverse DNS to determine if a particular IP is covered by it or not.&lt;BR /&gt;In most cases, this will fail.&lt;/P&gt;
&lt;P&gt;Another way to get the information is via Passive DNS:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk161612&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;This requires your gateway to be between your clients and their DNS query as well as other possible changes.&lt;/P&gt;
&lt;P&gt;You are better off defining FDQN Domain Objects here.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 03:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240035#M40059</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-30T03:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Domain Object</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240037#M40060</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So for my requirement we can't achieve by only create domain object?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 03:59:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240037#M40060</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2025-01-30T03:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Domain Object</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240089#M40063</link>
      <description>&lt;P&gt;The only way to make a non-FQDN Domain object "work properly" is to leverage Passive DNS, which may require networking changes.&lt;/P&gt;
&lt;P&gt;If you can't make those changes, you will need to use FDQN Domain Objects (which are resolved via forward lookup).&lt;BR /&gt;However, if the DNS servers used by the clients and gateways are different and they resolve the FDQNs differently (e.g. because of Geolocation or similar), you will also have issues.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 14:55:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Understanding-Domain-Object/m-p/240089#M40063</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-30T14:55:43Z</dc:date>
    </item>
  </channel>
</rss>

