<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R82 http proxy and dns proxy forwarding domains not working in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258164#M43562</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;on our Gateway Cluster (Elastic XL) we have the http Proxy (Non transparent) enabled.&lt;/P&gt;&lt;P&gt;Without configured DNS proxy Forwarding Domains this works.&lt;/P&gt;&lt;P&gt;After configured DNS Proxy Forwarding and restart the WSDNSD (or CPSTOP, CPSTART), Internet via Proxy don't work anymore.&lt;/P&gt;&lt;P&gt;When i removed the entry for DNS proxy Forwarding and restart the WSDNSD, Internet via proxy works again.&lt;/P&gt;&lt;P&gt;The Logs show the connection is reject because of Proxy: internal error; Connection was rejected due to internal error.&lt;/P&gt;&lt;P&gt;The error described in&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk110013" target="_blank"&gt;sk110013 - How to configure Check Point Security Gateway as HTTP/HTTPS Proxy&lt;/A&gt;&amp;nbsp;says:&amp;nbsp;&lt;SPAN&gt;DNS server is available but no record for the URL request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have no idea why this could not be resolved?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cat /etc/resolv.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/dnsmasq_xlate on Thu Sep 25 10:01:14 2025&lt;BR /&gt;#&lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;#&lt;BR /&gt;server 127.0.0.1&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cat /etc/dnsmasq.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/dnsmasq_xlate on Thu Sep 25 10:01:14 2025&lt;BR /&gt;#&lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;#&lt;BR /&gt;bind-interfaces&lt;BR /&gt;cache-size=1000&lt;BR /&gt;no-poll&lt;BR /&gt;listen-address=127.0.0.1&lt;BR /&gt;interface=bond3.706&lt;BR /&gt;server=/google.com/8.8.8.8&lt;BR /&gt;server=/#/1.1.1.1&lt;BR /&gt;server=/#/1.0.0.1&lt;BR /&gt;server=/#/9.9.9.9&lt;BR /&gt;conf-dir=/etc/dnsmasq.d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;netstat -tulpen | grep dnsmasq&lt;BR /&gt;tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN 0 94223101 10214/dnsmasq&lt;BR /&gt;tcp 0 0 10.10.6.254:53 0.0.0.0:* LISTEN 0 94223098 10214/dnsmasq&lt;BR /&gt;udp 0 0 127.0.0.1:53 0.0.0.0:* 0 94223100 10214/dnsmasq&lt;BR /&gt;udp 0 0 10.10.6.254:53 0.0.0.0:* 0 94223097 10214/dnsmasq&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All DNS could be locally resolved:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;# dig amazon.com&lt;/P&gt;&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7.cp998000096 &amp;lt;&amp;lt;&amp;gt;&amp;gt; amazon.com&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 56994&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1&lt;/P&gt;&lt;P&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 512&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;amazon.com. IN A&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;BR /&gt;amazon.com. 900 IN A 52.94.236.248&lt;BR /&gt;amazon.com. 900 IN A 54.239.28.85&lt;BR /&gt;amazon.com. 900 IN A 205.251.242.103&lt;/P&gt;&lt;P&gt;;; Query time: 11 msec&lt;BR /&gt;;; SERVER: 127.0.0.1#53(127.0.0.1)&lt;BR /&gt;;; WHEN: Thu Sep 25 10:05:13 CEST 2025&lt;BR /&gt;;; MSG SIZE rcvd: 87&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;dig google.com&lt;/P&gt;&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7.cp998000096 &amp;lt;&amp;lt;&amp;gt;&amp;gt; google.com&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 16468&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1&lt;/P&gt;&lt;P&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 512&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;google.com. IN A&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;BR /&gt;google.com. 300 IN A 142.251.36.206&lt;/P&gt;&lt;P&gt;;; Query time: 22 msec&lt;BR /&gt;;; SERVER: 127.0.0.1#53(127.0.0.1)&lt;BR /&gt;;; WHEN: Thu Sep 25 10:04:38 CEST 2025&lt;BR /&gt;;; MSG SIZE rcvd: 55&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Michael&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2025 08:10:06 GMT</pubDate>
    <dc:creator>Michael134890</dc:creator>
    <dc:date>2025-09-25T08:10:06Z</dc:date>
    <item>
      <title>R82 http proxy and dns proxy forwarding domains not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258164#M43562</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;on our Gateway Cluster (Elastic XL) we have the http Proxy (Non transparent) enabled.&lt;/P&gt;&lt;P&gt;Without configured DNS proxy Forwarding Domains this works.&lt;/P&gt;&lt;P&gt;After configured DNS Proxy Forwarding and restart the WSDNSD (or CPSTOP, CPSTART), Internet via Proxy don't work anymore.&lt;/P&gt;&lt;P&gt;When i removed the entry for DNS proxy Forwarding and restart the WSDNSD, Internet via proxy works again.&lt;/P&gt;&lt;P&gt;The Logs show the connection is reject because of Proxy: internal error; Connection was rejected due to internal error.&lt;/P&gt;&lt;P&gt;The error described in&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk110013" target="_blank"&gt;sk110013 - How to configure Check Point Security Gateway as HTTP/HTTPS Proxy&lt;/A&gt;&amp;nbsp;says:&amp;nbsp;&lt;SPAN&gt;DNS server is available but no record for the URL request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have no idea why this could not be resolved?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cat /etc/resolv.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/dnsmasq_xlate on Thu Sep 25 10:01:14 2025&lt;BR /&gt;#&lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;#&lt;BR /&gt;server 127.0.0.1&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cat /etc/dnsmasq.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/dnsmasq_xlate on Thu Sep 25 10:01:14 2025&lt;BR /&gt;#&lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;#&lt;BR /&gt;bind-interfaces&lt;BR /&gt;cache-size=1000&lt;BR /&gt;no-poll&lt;BR /&gt;listen-address=127.0.0.1&lt;BR /&gt;interface=bond3.706&lt;BR /&gt;server=/google.com/8.8.8.8&lt;BR /&gt;server=/#/1.1.1.1&lt;BR /&gt;server=/#/1.0.0.1&lt;BR /&gt;server=/#/9.9.9.9&lt;BR /&gt;conf-dir=/etc/dnsmasq.d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;netstat -tulpen | grep dnsmasq&lt;BR /&gt;tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN 0 94223101 10214/dnsmasq&lt;BR /&gt;tcp 0 0 10.10.6.254:53 0.0.0.0:* LISTEN 0 94223098 10214/dnsmasq&lt;BR /&gt;udp 0 0 127.0.0.1:53 0.0.0.0:* 0 94223100 10214/dnsmasq&lt;BR /&gt;udp 0 0 10.10.6.254:53 0.0.0.0:* 0 94223097 10214/dnsmasq&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All DNS could be locally resolved:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;# dig amazon.com&lt;/P&gt;&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7.cp998000096 &amp;lt;&amp;lt;&amp;gt;&amp;gt; amazon.com&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 56994&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1&lt;/P&gt;&lt;P&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 512&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;amazon.com. IN A&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;BR /&gt;amazon.com. 900 IN A 52.94.236.248&lt;BR /&gt;amazon.com. 900 IN A 54.239.28.85&lt;BR /&gt;amazon.com. 900 IN A 205.251.242.103&lt;/P&gt;&lt;P&gt;;; Query time: 11 msec&lt;BR /&gt;;; SERVER: 127.0.0.1#53(127.0.0.1)&lt;BR /&gt;;; WHEN: Thu Sep 25 10:05:13 CEST 2025&lt;BR /&gt;;; MSG SIZE rcvd: 87&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;dig google.com&lt;/P&gt;&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7.cp998000096 &amp;lt;&amp;lt;&amp;gt;&amp;gt; google.com&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; Got answer:&lt;BR /&gt;;; -&amp;gt;&amp;gt;HEADER&amp;lt;&amp;lt;- opcode: QUERY, status: NOERROR, id: 16468&lt;BR /&gt;;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1&lt;/P&gt;&lt;P&gt;;; OPT PSEUDOSECTION:&lt;BR /&gt;; EDNS: version: 0, flags:; udp: 512&lt;BR /&gt;;; QUESTION SECTION:&lt;BR /&gt;;google.com. IN A&lt;/P&gt;&lt;P&gt;;; ANSWER SECTION:&lt;BR /&gt;google.com. 300 IN A 142.251.36.206&lt;/P&gt;&lt;P&gt;;; Query time: 22 msec&lt;BR /&gt;;; SERVER: 127.0.0.1#53(127.0.0.1)&lt;BR /&gt;;; WHEN: Thu Sep 25 10:04:38 CEST 2025&lt;BR /&gt;;; MSG SIZE rcvd: 55&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Michael&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 08:10:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258164#M43562</guid>
      <dc:creator>Michael134890</dc:creator>
      <dc:date>2025-09-25T08:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: R82 http proxy and dns proxy forwarding domains not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258240#M43573</link>
      <description>&lt;P&gt;dnsmasq logs to syslog a.k.a. /var/log/messages&lt;BR /&gt;Anything useful there?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 19:02:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258240#M43573</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-25T19:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: R82 http proxy and dns proxy forwarding domains not working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258306#M43595</link>
      <description>&lt;P&gt;Output from /var/log/messages:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;dnsmasq_xlate: Starting dnsmasq_xlate as default mode&lt;BR /&gt;dnsmasq_xlate: Updating dnsmasq configuration&lt;BR /&gt;dnsmasq_xlate: Restarting dnsmasq&lt;BR /&gt;dnsmasq[10125]: exiting on receipt of SIGTERM&lt;BR /&gt;dnsmasq[10214]: started, version 2.76 cachesize 1000&lt;BR /&gt;dnsmasq[10214]: compile time options: IPv6 GNU-getopt no-DBus no-i18n IDN DHCP DHCPv6 no-Lua TFTP no-conntrack ipset au&lt;BR /&gt;th nettlehash no-DNSSEC loop-detect inotify&lt;BR /&gt;dnsmasq[10214]: using nameserver 9.9.9.9#53 for default&lt;BR /&gt;dnsmasq[10214]: using nameserver 1.0.0.1#53 for default&lt;BR /&gt;dnsmasq[10214]: using nameserver 1.1.1.1#53 for default&lt;BR /&gt;dnsmasq[10214]: using nameserver 8.8.8.8#53 for domain google.com&lt;BR /&gt;dnsmasq[10214]: read /etc/hosts - 15 addresses&lt;BR /&gt;dnsmasq[10214]: using nameserver 9.9.9.9#53 for default&lt;BR /&gt;dnsmasq[10214]: using nameserver 1.0.0.1#53 for default&lt;BR /&gt;dnsmasq[10214]: using nameserver 1.1.1.1#53 for default&lt;BR /&gt;dnsmasq[10214]: using nameserver 8.8.8.8#53 for domain google.com&lt;BR /&gt;dnsmasq[10214]: ignoring nameserver 127.0.0.1 - local interface&lt;BR /&gt;xpand[27580]: log info: objectName: DNS,administrator: admin, operation: Set Object, facility: Web-UI, message: primary&lt;BR /&gt;DNS server in forwarding domain google.com is set to 8.8.8.8&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;But no erros or anything else&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 12:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R82-http-proxy-and-dns-proxy-forwarding-domains-not-working/m-p/258306#M43595</guid>
      <dc:creator>Michael134890</dc:creator>
      <dc:date>2025-09-26T12:30:50Z</dc:date>
    </item>
  </channel>
</rss>

