<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252214#M42232</link>
    <description>&lt;P&gt;I created a new "domain" entry in the object explorer : .downloads.dell.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jun 2025 04:50:06 GMT</pubDate>
    <dc:creator>Ruud</dc:creator>
    <dc:date>2025-06-30T04:50:06Z</dc:date>
    <item>
      <title>Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252138#M42213</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Our server techs requested that i allow their iDrac devices https access to the url downloads.dell.com to download their updates.&lt;BR /&gt;downloads.dell.com however is hosted on the akamai cdn network, so there are a lot of servers behind that url.&lt;/P&gt;&lt;P&gt;It works using the url as a firewall object, but only for 1 akamai server, the rest is blocked. It seems like only the ip address of the server that was received on the initial DNS request works, as this remains in the cache. The iDracs however are trying to connect multiple akamai servers, which will be blocked. (no clue how the iDracs do get a list of hosts on that url)&lt;/P&gt;&lt;P&gt;I could create a firewall object containing a list of known akamai servers to resolve this, but that list will change all the time, and it's not a given that all of these servers will host the dell download files.&lt;/P&gt;&lt;P&gt;I have seen this before when creating rules for servers on azure etc.&lt;/P&gt;&lt;P&gt;Is there a neat way to resolve this ? Perhaps a firewall object that dynamically checks the server ranges from akamai etc ?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 13:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252138#M42213</guid>
      <dc:creator>Ruud</dc:creator>
      <dc:date>2025-06-27T13:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252142#M42216</link>
      <description>&lt;P&gt;When you say "URL as a firewall object" please clarify which object type was used here.&lt;BR /&gt;Also clarify version/JHF in use.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 17:08:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252142#M42216</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-27T17:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252214#M42232</link>
      <description>&lt;P&gt;I created a new "domain" entry in the object explorer : .downloads.dell.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 04:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252214#M42232</guid>
      <dc:creator>Ruud</dc:creator>
      <dc:date>2025-06-30T04:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252217#M42233</link>
      <description>&lt;P&gt;Do the gateways and requesting client use the same DNS server settings and resolve it the same way?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally which version/JHF is the gateway in question?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 06:52:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252217#M42233</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-30T06:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252285#M42268</link>
      <description>&lt;P&gt;Unless your gateway and clients are using the exact same DNS server (and getting the same results), this object type won't work well.&lt;BR /&gt;There are other options that might work better, and I cover them in the &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Web-Filtering-Best-Practices-June-2025-Video-and-Slides/m-p/252092#M49369" target="_self"&gt;Web Filtering Best Practices&lt;/A&gt; session I periodically run.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 16:27:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252285#M42268</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-30T16:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252302#M42276</link>
      <description>&lt;P&gt;Make sure its checked as fully qualified domain name.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 19:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252302#M42276</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-30T19:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Allow rule for site hosted on akamai CDN, only the first dns response seems to work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252319#M42283</link>
      <description>&lt;P&gt;We run r81.20 at our gateways. But the DNS server thing might be the issue.&lt;BR /&gt;&lt;BR /&gt;Our server guys are renewing their server infrastructure and started using new DNS servers, but the network equipment hasn't been changed yet.&amp;nbsp; So, this is a good reason to pick up that task for sure.&lt;/P&gt;&lt;P&gt;Going to look at Phoneboys session for sure as well.&lt;BR /&gt;&lt;BR /&gt;Thanks for your responses guys !&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 06:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Allow-rule-for-site-hosted-on-akamai-CDN-only-the-first-dns/m-p/252319#M42283</guid>
      <dc:creator>Ruud</dc:creator>
      <dc:date>2025-07-01T06:44:06Z</dc:date>
    </item>
  </channel>
</rss>

