<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain object failure in R80.10 (sk120558) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26257#M5330</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.&amp;nbsp; Well, the SK says it is fixed in R80.10, Take 42.&amp;nbsp; Since this is running Take 112, I guess I'll reach out to TAC.&amp;nbsp; thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Nov 2018 18:14:55 GMT</pubDate>
    <dc:creator>phlrnnr</dc:creator>
    <dc:date>2018-11-15T18:14:55Z</dc:date>
    <item>
      <title>Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26246#M5319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just running pass if anyone else has come across this one&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62658_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;DNS resolves OK manually on CLI but the problem is that both SK and SR engineer wants kernel debug that potentially may overload the FW. Considering that this is business critical firewall potentially causing $100k loss every minute it is dead and it's remote, I'm very reluctant to run debugs. Asked support engineer to come up with something else but hit the stone wall (that's a topic i really want to start - when will CP will come up with better debugging &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing graceful cluster reboot (standby reboot &amp;gt; failover &amp;gt; new standby reboot) seems to have "fixed" it for now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone with better ideas regarding domain object "checks" / tricks in R80.10 before diving into kernel debug?&lt;/P&gt;&lt;P&gt;This is plain firewall cluster (5900) with only firewall and IA blades, nothing fancy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 20:54:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26246#M5319</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-29T20:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26247#M5320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moving this to &lt;A href="https://community.checkpoint.com/space/2030"&gt;General Product Topics&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;It's possible the kernel DNS lookup timed out somehow before it got a response.&lt;/P&gt;&lt;P&gt;Which would explain why it worked when you checked on the appliance.&lt;/P&gt;&lt;P&gt;I'm guessing that would show on the debugs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 22:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26247#M5320</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-29T22:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26248#M5321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess my description was not good enough - it wasn't just a temporary issue but full stop on domain object based rules. They didn't work and logs were full with those alerts. Whilst manual lookup worked just fine.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 05:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26248#M5321</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-30T05:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26249#M5322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That sounds like the DNS resolution process got hung/crashed somehow.&lt;/P&gt;&lt;P&gt;And yeah, we'd probably need some detailed debugs to see what's going on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 14:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26249#M5322</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-30T14:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26250#M5323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turned out that we had it all over the place including VSX firewalls running R80.10 and regular ones. Since I saw it on standby cluster members too, I collected debug from one of them and it turned out to be the same bug as SK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I would like to bit more info on actual root cause as SK is very short on it. How come that most firewalls have got the same problem now - is it DNS specific? Is it actual object specific?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;"&lt;EM&gt;Internal failure in DNS health check state of Domain Objects&lt;/EM&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 15:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26250#M5323</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-30T15:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26251#M5324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking at the various internal information I have access to, there's not much more than is in the SK.&lt;/P&gt;&lt;P&gt;The good news is that there is a hotfix for the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:20:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26251#M5324</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-30T16:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26252#M5325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for trying Dameon!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:33:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26252#M5325</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-30T16:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26253#M5326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Couldn't just give up on it as I wanted the explanation. Eventually pulled together information from our DNS team that did some planned work on weekend which meant that DNS was not totally down but could have apparently had "slow" responses. And it looks like that's enough to kill the DNS cache for domain objects in majority of our firewalls.&lt;/P&gt;&lt;P&gt;I was able to replicate it in the lab (sort of) by changing DNS IP temporary to a dummy IP address. To accelerate the process I did cpstop/cpstart so FW started using new IPs which in turn would not respond. And it didn't take that long before I got the same alerts there. And it seems like it never recovers from it, until you cpstop/cpstart again the gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In nutshell - if&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you use domain objects and&lt;/LI&gt;&lt;LI&gt;have a DNS hiccup in the network and&lt;/LI&gt;&lt;LI&gt;start seeing DNS alerts in logs (like one above) and&lt;/LI&gt;&lt;LI&gt;don't have the hotfix&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cpstop/cpstart on the gateway seems to restore the functionality as long as DNS is functioning again correctly.. In cluster case you may do graceful cpstop/cpstart on each member (standby/fail over/standby)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 14:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26253#M5326</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-31T14:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26254#M5327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Appreciate your diligence in tracking this down. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2018 14:46:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26254#M5327</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-31T14:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26255#M5328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this bug exist in R80.20 as well?&amp;nbsp; The SK only shows R80.10 as being affected, but I'm seeing similar symptoms in R80.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More specifically, I'm seeing something similar with R80.20 Mgmt and R80.10 + Jumbo 112 VSX GWs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 16:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26255#M5328</guid>
      <dc:creator>phlrnnr</dc:creator>
      <dc:date>2018-11-15T16:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26256#M5329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The &lt;EM&gt;&lt;STRONG&gt;gateway&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;in your example is still R80.10, which is where the name resolution takes place.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 17:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26256#M5329</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-15T17:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26257#M5330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.&amp;nbsp; Well, the SK says it is fixed in R80.10, Take 42.&amp;nbsp; Since this is running Take 112, I guess I'll reach out to TAC.&amp;nbsp; thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 18:14:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26257#M5330</guid>
      <dc:creator>phlrnnr</dc:creator>
      <dc:date>2018-11-15T18:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26258#M5331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/47831"&gt;Kaspars Zibarts&lt;/A&gt;, was TAC able to tell you what the hotfix actually did?&amp;nbsp; Does it monitor the service and restart it if it crashes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 18:32:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26258#M5331</guid>
      <dc:creator>phlrnnr</dc:creator>
      <dc:date>2018-11-15T18:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26259#M5332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately I couldn't find explanation in the SR even I asked for it. Just hotfixes&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 21:12:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/26259#M5332</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-11-15T21:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Domain object failure in R80.10 (sk120558)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/55704#M11147</link>
      <description>&lt;P&gt;Did anyone try to do dns flush?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 12:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-object-failure-in-R80-10-sk120558/m-p/55704#M11147</guid>
      <dc:creator>Ray_Xiao</dc:creator>
      <dc:date>2019-06-13T12:51:05Z</dc:date>
    </item>
  </channel>
</rss>

