<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ForeScout in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31729#M6639</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;You can follow the configuration based on the link below.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_DNS_Enforce_1.2.pdf" title="https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_DNS_Enforce_1.2.pdf"&gt;https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_DNS_Enforce_1.2.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Feb 2019 03:23:04 GMT</pubDate>
    <dc:creator>Poh_Seng_Anthon</dc:creator>
    <dc:date>2019-02-11T03:23:04Z</dc:date>
    <item>
      <title>ForeScout</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31727#M6637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any experience with ForeScout products?&amp;nbsp; One of my customers has asked the question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;We are exploring options on Wi-Fi portals for guest access on our Wi-Fi.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;One option is to utilize our Forescout however we then need a local DNS which can resolve the local Forescout device but also any subsequent DNS requests.&lt;BR /&gt; &lt;BR /&gt;Can the [Check Point] firewall do this or can it acts as a DNS forwarder to our internal DNS server – and if so is there any issue / concern with this approach?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know well ForeScount well enough (at all!) to immediately answer him.&amp;nbsp; His question doesn't tell me how ForeScout DNS works so I wondered if anyone else happens to know or has done a similar thing in their environment?&amp;nbsp; My first thought is that he really doesn't want visitors and guests using his internal DNS.&amp;nbsp; Does anyone with experience with this product know if that's what he probably means?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Feb 2019 18:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31727#M6637</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-02-09T18:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: ForeScout</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31728#M6638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No ForeScout expert here, but I suspect that I can extrapolate what your client is trying to achieve.&lt;/P&gt;&lt;P&gt;They are likely trying to implement ForeScout NAC and use it to perform DNS forwarding for guests.&lt;/P&gt;&lt;P&gt;If this is the case and all Check Point devices have to do is to resolve the ForeScout devices names then you can even hard code them in Gaia of your Check Point devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are actually looking to use Check Point as forwarders, these capabilities are present in SMB appliances with embedded Gaia:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78308_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...but not in the enterprise models which rely on a dedicated external DNS infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is likely you can jury-rig something to make it work, but I would not recommend it.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Feb 2019 20:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31728#M6638</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-02-09T20:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: ForeScout</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31729#M6639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;You can follow the configuration based on the link below.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_DNS_Enforce_1.2.pdf" title="https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_DNS_Enforce_1.2.pdf"&gt;https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_DNS_Enforce_1.2.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2019 03:23:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ForeScout/m-p/31729#M6639</guid>
      <dc:creator>Poh_Seng_Anthon</dc:creator>
      <dc:date>2019-02-11T03:23:04Z</dc:date>
    </item>
  </channel>
</rss>

