<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN routing in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192438#M9481</link>
    <description>&lt;P&gt;It should be possible with your existing appliance if it is managed with a Smart-1 (Cloud).&lt;BR /&gt;This will also require configuring Inbound HTTPS Inspection, which will require a wildcard certificate.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Sep 2023 15:44:04 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-09-12T15:44:04Z</dc:date>
    <item>
      <title>FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187643#M9231</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Would like to know if it is possible with a 1500 device to route FQDN. Would like to have 1 Public IP Address but route (NAT) different FQDN to internal IP Addresses.&lt;/P&gt;&lt;P&gt;If not possible using R81.10 which devices (FW), can be used?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 08:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187643#M9231</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-07-26T08:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187646#M9232</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179797" target="_self"&gt;R81.10.05 for Quantum Spark Appliances&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;In Updatable objects and FQDN in Locally Managed mode (NAT / SSL / Threat Prevention) - Use fully qualified domain name (FQDN) object in the NAT policy, Threat Prevention, and SSL exceptions. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187646#M9232</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-26T09:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187652#M9233</link>
      <description>&lt;P&gt;Thanks for the quick reply,&lt;/P&gt;&lt;P&gt;we are using FW R81.10.07, is there some directions how to put the FQDN in NAT?&lt;/P&gt;&lt;P&gt;Greets,&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 09:57:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187652#M9233</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-07-26T09:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187690#M9234</link>
      <description>&lt;P&gt;Create the relevant object, create a rule involving it?&lt;BR /&gt;phoneboy.com here is an object of type Domain.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21895i89BB88B18AB83639/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 13:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187690#M9234</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-26T13:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187692#M9235</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Defining-NAT-Control.htm?Highlight=FQDN" target="_blank"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Defining-NAT-Control.htm?Highlight=FQDN&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 13:44:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187692#M9235</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-26T13:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187704#M9237</link>
      <description>&lt;P&gt;That would exactly be my question, how to put a FQDN in "original Destination" in your screen shot it is phoneboy.com how is that created?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:22:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187704#M9237</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-07-26T14:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187739#M9238</link>
      <description>&lt;P&gt;You create an object of type Domain.&lt;BR /&gt;It can be done while creating the manual NAT rule like so:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 947px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21900iC3A4310A7CB22FC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 16:48:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187739#M9238</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-26T16:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187743#M9239</link>
      <description>&lt;P&gt;I tried that but how to make a reference to the internal IP Address? The Internal DNS Server does refers to the Privat IP Address however coming from outside it is not being sent to the Internal IP.&amp;nbsp; In Network objects is the FQDN ftp....com as domain name, and have NAT Rule any; ftp...com; any; Original; Original;Original&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also tried Translated Destination to Internal IP but does not cooperate either.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 17:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187743#M9239</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-07-26T17:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187761#M9240</link>
      <description>&lt;P&gt;To get the internal FQDN, you will need to configure the gateway to use Internal DNS servers, not the external one.&lt;BR /&gt;If this isn't working with an internal IP (i.e using a host object), then we need to see more about the configuration including a simple network topology and the precise configuration made (with sensitive details redacted).&amp;nbsp;&lt;BR /&gt;Note if you are using the firewall's external IP for inbound communication, do not create a NAT rule, use a Server object instead.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 18:39:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/187761#M9240</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-26T18:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/191928#M9440</link>
      <description>&lt;P&gt;Hello to all hope everyone is healthy, sorry for not replying sooner seems more work than play right now. Assume the same for you all.&lt;/P&gt;&lt;P&gt;First of all we always configure the firewall to use internal DNS Servers, particularly for Remote users. The FW, when pinging the FQDN returns the correct internal IP Address.&lt;/P&gt;&lt;P&gt;Regarding NAT we have added manually rule:&lt;/P&gt;&lt;P&gt;Source = any; Destination = FQDN; Service=any; Translated source = Orginal; Translated destination = FQDN; translated service= orginal&lt;/P&gt;&lt;P&gt;We are running R81.10.07 (996001430) FW&lt;/P&gt;&lt;P&gt;Hope to find a solution, probably something simple that I am missing.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 15:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/191928#M9440</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-09-07T15:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/191948#M9441</link>
      <description>&lt;P&gt;You have the same destination for the original and translated packet.&lt;BR /&gt;You will need to use the external IP (or an FQDN that resolves to the external IP) as the destination IP.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 17:52:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/191948#M9441</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-07T17:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192023#M9447</link>
      <description>&lt;P&gt;I think i missunderstand something, the objective is to use 1 public IP Address, however when externally the url is put in, for example, ftp.y-it.net&amp;nbsp; that should go to the internal server ftp.y-it.net when, from extern the url &lt;A href="http://www.y-it.nt" target="_blank"&gt;www.y-it.net&amp;nbsp;&lt;/A&gt;then that should be routed or Nated to a different internal server. If we put in the orginal destination the Public IP everything will go to the one server, whether using domain name (using the Internal DNS Servr), or IP Address is irrelevant.&lt;/P&gt;&lt;P&gt;presently, for example putting in the url &lt;A href="http://www.y-it.net" target="_blank"&gt;www.y-it.net&lt;/A&gt;&amp;nbsp;it goes to the correct Public IP Address, however the Firewall does not send it to the proper internal IP Address.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 10:26:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192023#M9447</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-09-08T10:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192088#M9452</link>
      <description>&lt;P data-unlink="true"&gt;Is this IP the external IP of the gateway?&lt;BR /&gt;In this case, you will need to create one or more server objects instead of NAT rules.&lt;BR /&gt;If this is not the external IP of the gateway, then you will need to create more specific NAT rules (based on connection port).&lt;BR /&gt;Note that if two or more such servers require the same port (e.g. you've got www.y-it.net&amp;nbsp;and www2.y-it.net using HTTPS), this isn't supported and will not work.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 02:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192088#M9452</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-09T02:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192097#M9457</link>
      <description>&lt;P&gt;Yes thank you very much for the info this is exactly what I wanted to know. However I do not understand why this should not be possible to route or NAT using FQDN instead of IP Addresses. This would be a very simple change and an improvement. Using the Domainname setting in Objects is really so not of an use.&lt;/P&gt;&lt;P&gt;BTW in this particular case we are using 2 Internet connections, one is SDSL with 5 Public IP Addresses for hosts which can easily be NATed using the Servers setting, and an addtional VDSL connection with 1 Public IP Address.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would still strongly recommend the change for Checkpoint to be able use DNS for routing and NAT.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 07:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192097#M9457</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-09-09T07:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192099#M9458</link>
      <description>&lt;P&gt;I should explain, I know the Internet works using IP, however in the header is also the FQDN request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 07:52:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192099#M9458</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-09-09T07:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192248#M9471</link>
      <description>&lt;P&gt;This may be possible if the device is managed by a Smart-1 device (i.e. not through the local WebUI).&lt;BR /&gt;More precisely, this requires inbound HTTPS Inspection since almost all web traffic is TLS encrypted these days with a certificate that matches all the possible websites (can be a wildcard).&lt;BR /&gt;Without this, it is impossible to see the relevant headers to act on them.&lt;BR /&gt;This definitely won't work with unencrypted HTTP traffic as that requires functionality that doesn't exist in the products (SMB or otherwise).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, Inbound HTTPS Inspection is not available for locally managed SMB devices:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178604" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk178604&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 15:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192248#M9471</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-11T15:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192374#M9474</link>
      <description>&lt;P&gt;Thanks for the info, actually this was my very first question: "&lt;SPAN&gt;If not possible using R81.10 which devices (FW), can be used? "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If it is&amp;nbsp; possible using managed Software what are the requirements, and https inspection?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 06:55:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192374#M9474</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2023-09-12T06:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192438#M9481</link>
      <description>&lt;P&gt;It should be possible with your existing appliance if it is managed with a Smart-1 (Cloud).&lt;BR /&gt;This will also require configuring Inbound HTTPS Inspection, which will require a wildcard certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 15:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/FQDN-routing/m-p/192438#M9481</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-12T15:44:04Z</dc:date>
    </item>
  </channel>
</rss>

