<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering using DNS  in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22905#M4565</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Deamon and Gunther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answers. I agree that using URLF is the best possible solution. I am trying to figure out what is the best solution if I can't route end users traffic through the gateway.&amp;nbsp;I am thinking about Endpoint security with URLF blade will be a suitable replacement but it is not deployed at the moment. what do you think?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Aug 2018 08:13:53 GMT</pubDate>
    <dc:creator>Shahar_Grober</dc:creator>
    <dc:date>2018-08-30T08:13:53Z</dc:date>
    <item>
      <title>URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22896#M4556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had an interesting discussion about&amp;nbsp;performing URL filtering using DNS only instead of&amp;nbsp;URLs which allows faster resolving and will allow controlling of remote offices internet traffic without deploying URL Filtering on remote gateways or force redirection of internet traffic through the&amp;nbsp;corporate gateway. This means that all DNS requests from remote offices are inspected by the gateway and allowed/blocked based on the DNS&amp;nbsp;resolving. I know that the Anti-bot uses DNS for malicious website and also according to the "the&amp;nbsp;R80.x Security Gateway Architecture (Content Inspection)" the RAD is using DNS as well but I am wandering if the URL filtering can be done based on the DNS request of the remote hosts or the http/https connection has to be opened and pass through the gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is similar to OpenDNS solution for Web Content filtering&amp;nbsp;&lt;A class="link-titled" href="https://support.opendns.com/hc/en-us/articles/227988047-Web-Content-Filtering-and-Security" title="https://support.opendns.com/hc/en-us/articles/227988047-Web-Content-Filtering-and-Security"&gt;Web Content Filtering and Security – OpenDNS&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insights are welcome.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 12:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22896#M4556</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-08-28T12:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22897#M4557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i would suggest&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92743&amp;amp;partition=Advanced&amp;amp;product=URL"&gt;sk92743 ATRG: URL Filtering&lt;/A&gt; for technical details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 12:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22897#M4557</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-28T12:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22898#M4558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already&amp;nbsp;looked at it.&amp;nbsp;There is no mention to use of DNS by URLF or RAD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2 style="color: #333333; background-color: #ffffff; font-weight: bold; font-size: 22px; padding: 10px 0px 0px;"&gt;L Filtering Categorization Flow&lt;/H2&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;IMG alt="" src="https://sc1.checkpoint.com/sc/SolutionsStatics/sk73220/urlf_categorization_a.png" style="border: none;" /&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;IMG alt="" height="210" src="https://sc1.checkpoint.com/sc/SolutionsStatics/sk73220/urlf_categorization_b.png" style="border: none;" width="630" /&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;although the "&lt;SPAN style="color: #333333;"&gt;R80.x Security Gateway Architecture (Content Inspection)" says that there is use of DNS with RAD&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69887_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;It would be nice to know if Check Point can support the scenario in my original question or not&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 12:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22898#M4558</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-08-28T12:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22899#M4559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not think that this is possible - URLF checks the URL in the internal database first and, if niot successfull, sends a request to online detection service. So, no DNS is contacted here before the URL categorization is finished. The OpenDNS solution rather&amp;nbsp;is a competitor&amp;nbsp;to CP URLF with very a small set of features.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 13:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22899#M4559</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-28T13:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22900#M4560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information &lt;SPAN style="text-decoration: underline;"&gt;Gunthar,&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No argue that CP can provide better functionality than OpenDNS. I was just wandering if Check Point can provide similar functionality giving the fact that the infrastructure already exist with Anti-bot to block malicious DNS requests&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 13:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22900#M4560</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-08-28T13:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22901#M4561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CP is using very similar functionality, but does not disguise itself as DNS server &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Did you read sk31727 and sk35484 already ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 14:12:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22901#M4561</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-28T14:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22902#M4562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is good information. bottom line is that&amp;nbsp;Check Point&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;products do not implement DNS server functionality and therefore cannot perform URL filtering based on DNS requests.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 14:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22902#M4562</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-08-28T14:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22903#M4563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS doesn't factor into URL filtering at all.&lt;/P&gt;&lt;P&gt;The main problem with using DNS as I see it is that a number of sites could use the same IP address.&lt;/P&gt;&lt;P&gt;You may allow access to some sites on the same IP, but block others.&lt;/P&gt;&lt;P&gt;Also I could access a given IP without doing a DNS lookup (e.g. Because of caching, poisoned or otherwise).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2018 15:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22903#M4563</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-28T15:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22904#M4564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me put it like this: With OpenDNS, you&amp;nbsp;use the DNS lookup for performing URLF. With CP URLF, no DNS request will be made at all if the URL is blocked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2018 07:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22904#M4564</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-29T07:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22905#M4565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Deamon and Gunther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answers. I agree that using URLF is the best possible solution. I am trying to figure out what is the best solution if I can't route end users traffic through the gateway.&amp;nbsp;I am thinking about Endpoint security with URLF blade will be a suitable replacement but it is not deployed at the moment. what do you think?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 08:13:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22905#M4565</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-08-30T08:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22906#M4566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either Endpoint URLF or Capsule Cloud would be reasonable in these cases.&lt;/P&gt;&lt;P&gt;Both would work regardless of where the end users are.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 15:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22906#M4566</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-30T15:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering using DNS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22907#M4567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with &lt;A href="https://community.checkpoint.com/migrated-users/61362"&gt;Shahar Grober&lt;/A&gt;‌&lt;BR /&gt;it will be better if Checkpoint can perform dns filtering instead of relying on 3rd party appliances such as infoblox or other dns firewall outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2018 09:03:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URL-Filtering-using-DNS/m-p/22907#M4567</guid>
      <dc:creator>Ranokarno_Ranok</dc:creator>
      <dc:date>2018-12-13T09:03:21Z</dc:date>
    </item>
  </channel>
</rss>

