<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235362#M11841</link>
    <description>&lt;P&gt;What does your access policy look like?&lt;BR /&gt;If you're using any FQDN objects or Updatable Objects, we need to resolve those DNS domains to IP addresses, thus the gateway will need to issue DNS requests.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2024 15:28:38 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-12-11T15:28:38Z</dc:date>
    <item>
      <title>2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235295#M11835</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;No user activity, no security blades, only "baby vpn". All over the clock, regardless of the user activity, over the vpn are sent dns queries.&amp;nbsp;&lt;SPAN&gt;Quantum Spark 1570 Appliance&amp;nbsp; R81.10.10 (996002993)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For the last 24 hours it looks like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;... | stats dc(query) as distinct_query_count -&amp;gt; 923&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="qnsq.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28739i67F798B6604E97C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="qnsq.png" alt="qnsq.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dnsq2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28740i27469EFBEEEB06E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dnsq2.png" alt="dnsq2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Counts for each FQDN are similar, around 1900. FQDNs are mixed.&lt;/P&gt;&lt;P&gt;Looks like not related to any user traffic (tcpdump not showing any activity nor any dns queries on the internal interfaces).&lt;/P&gt;&lt;P&gt;Looks like autogenerated by gateway itself - almost 2M queries/day.&lt;/P&gt;&lt;P&gt;Some fgdns are "grepable" in prfm2.0, some not.&lt;/P&gt;&lt;P&gt;Why at all, why this FQDN-s (923 for the last 24 h), why every 45s (24*3600/1900 =~45) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Andrzej&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 10:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235295#M11835</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2024-12-11T10:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235362#M11841</link>
      <description>&lt;P&gt;What does your access policy look like?&lt;BR /&gt;If you're using any FQDN objects or Updatable Objects, we need to resolve those DNS domains to IP addresses, thus the gateway will need to issue DNS requests.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 15:28:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235362#M11841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-11T15:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235457#M11845</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;Thx for response. The policy is simple - everything into the tunnel ( 2 rules - one for private networks and the second for all others ) and reverse - only selected, private subnets (mostly mgmt). IoT is disabled, dynamic objects are not used - an old days classic policy ;-). Anyway, if using over fibers - no big problem. But over wireless networks 2M dns queries a day ( dns + ESP is about about 50 bytes ) uses&amp;nbsp; 100 MB/day for nothing and 3GB per month.&amp;nbsp; There is nothing dynamic in this vpn gateway.&amp;nbsp;How to disable this DNS queries? Maybe somebody knows?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Andrzej&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 10:33:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235457#M11845</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2024-12-12T10:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235459#M11846</link>
      <description>&lt;P&gt;Is the gateway maybe set as dns server for the clients? Maybe on accident? What if you run ipconfig on a few to verify this&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 11:01:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235459#M11846</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-12T11:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235463#M11847</link>
      <description>&lt;P&gt;Can you please try to turn off smart accel ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 11:21:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235463#M11847</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-12-12T11:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235464#M11848</link>
      <description>&lt;P&gt;No. No dns queries from any client,&amp;nbsp; Every 45 seconds each of the 935 FQDNs is beeing resolved (gateway sends requests to the DNS server, asking for it)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 11:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235464#M11848</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2024-12-12T11:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235466#M11852</link>
      <description>&lt;P&gt;I will try fwaccel off ...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 11:53:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235466#M11852</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2024-12-12T11:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235502#M11854</link>
      <description>&lt;P&gt;The only other things I can think of that MIGHT trigger DNS queries are Fast Accel (disabled by default) and SD-WAN (enabled by default).&lt;BR /&gt;Both of these are under Access Control &amp;gt; Firewall.&lt;BR /&gt;In any case, your best bet is to engage TAC so we can investigate.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 15:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235502#M11854</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-12T15:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235777#M11860</link>
      <description>&lt;P&gt;Hi please try to turn off smart accel via webUI (under Access Policy--&amp;gt;Fast Accel)&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2024 06:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/235777#M11860</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-12-15T06:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236010#M11866</link>
      <description>&lt;P&gt;I have a workaround for you that had been tested at a customers.&lt;/P&gt;
&lt;P&gt;To achieve this, you can add the following commands into userScript file:&lt;/P&gt;
&lt;PRE&gt;# cpwd_admin stop -name WSDNSD
# cpwd_admin detach -name WSDNSD&lt;/PRE&gt;
&lt;P&gt;No DNS queries will be sent when this is set - just test it on-the-fly using the commands on CLI!&lt;/P&gt;
&lt;P&gt;This WSDNSD behaviour was internally considered a bug by R&amp;amp;D (WSDNS is used as DNS resolver when the appliance is used as a HTTP/HTTPS proxy and WSDNSD makes requests for smartAccel, but it does the same requests even if both&amp;nbsp;HTTP/HTTPS proxy and smartAccel is not used/disabled),&amp;nbsp; but i am not sure if this has already been fixed in current firmware...&lt;/P&gt;
&lt;P&gt;The case in which this information has been collected was resolved by using internal objects in WebGUI - if you define FQDN objects as object something.com 8.8.8.8, no DNS request for this FQDN will be sent, but it will make more sense to disable WSDNSD than to define 935 internal objects here...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 14:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236010#M11866</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-17T14:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236086#M11867</link>
      <description>&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;WSDNSD works immediately! Talking about a userscript you think to schedule it into the&amp;nbsp; SystemManagement/Scheduler? I guess it should be executed by example 5 minutes after boot, until the fixed firmware release/upgrade?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 08:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236086#M11867</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2024-12-18T08:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236088#M11868</link>
      <description>&lt;P&gt;No, this is a 15x0x applance = SMB: &lt;A href="https://support.checkpoint.com/results/sk/sk52520" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk52520&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;SMBs use the userScript file to call custome commands during startup, so this is the place for the two lines !&lt;/P&gt;
&lt;P&gt;Give a Kudo if you like my post...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 08:49:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236088#M11868</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-18T08:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236310#M11871</link>
      <description>&lt;P&gt;I would rather not call this a solution but a workaround only ! I had been rather upset that R&amp;amp;D did not want to fix it.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 08:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/236310#M11871</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-19T08:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/237792#M11930</link>
      <description>&lt;P&gt;As i wrote above, R&amp;amp;D called this a bug but was not willing to fix that for the firmware showing the issue...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 10:28:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/237792#M11930</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-07T10:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/237793#M11931</link>
      <description>&lt;P&gt;Works perfect, but after any GUI changes the WSDNSD service is restarted . Cron -&amp;nbsp; each 15 minutes stop this service?&amp;nbsp; Is it possible to disable it permanently? Or the scheduler is the last hope? From GUI or to try cli?&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.spikefishsolutions.com/2016/04/enabling-cron-scheduling-services-on.html" target="_blank" rel="noopener"&gt;https://blog.spikefishsolutions.com/2016/04/enabling-cron-scheduling-services-on.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/Perform-scheduled-scripted-tasks-on-SMB-devices-without-using/td-p/40054" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/Perform-scheduled-scripted-tasks-on-SMB-devices-without-using/td-p/40054&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Job-Scheduler-to-stop-and-start-the-wsdnsd-process-on-Gaia-R80/td-p/94124" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Management/Job-Scheduler-to-stop-and-start-the-wsdnsd-process-on-Gaia-R80/td-p/94124&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 10:49:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/237793#M11931</guid>
      <dc:creator>chrominek</dc:creator>
      <dc:date>2025-01-07T10:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: 2M DNS queries per day via vpn for about 1k fqdn  - 1900+ each</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/237797#M11933</link>
      <description>&lt;P&gt;Strange - if WSDNSD service is detached from Watchdog at boot time, i would not expect this to happen!&lt;/P&gt;
&lt;P&gt;Other alternative suggested by R&amp;amp;D was&lt;/P&gt;
&lt;PRE&gt;watch -n 30 "$FWDIR/bin/cpwd_admin stop -name WSDNSD &amp;gt; /dev/null" &amp;amp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;This also should go into userScript and kills WSDNSD every 30s...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 10:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/2M-DNS-queries-per-day-via-vpn-for-about-1k-fqdn-1900-each/m-p/237797#M11933</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-07T10:58:09Z</dc:date>
    </item>
  </channel>
</rss>

