<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap in Threat Exposure Management</title>
    <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277806#M17</link>
    <description>&lt;P&gt;Yes, you can disable th DNS malware trap, this is an additional feature that could help prevent malware connections by intervening and DNS query level, without the need to inspect traffic to identify malware; but if you have Anti-virus and anti-bot protection enabled you're protected in any case.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2026 13:26:27 GMT</pubDate>
    <dc:creator>simonemantovani</dc:creator>
    <dc:date>2026-06-03T13:26:27Z</dc:date>
    <item>
      <title>Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277792#M10</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;We are trying to run a phishing training simulation, but the test links are being blocked by the Check Point firewall.&lt;/P&gt;&lt;P&gt;Although we have already configured rules in Access Control and added exceptions in Threat Prevention, the traffic is still getting blocked at the DNS layer. Our troubleshooting shows that the gateway's Malware DNS Trap (under Profiles → Optimized) is intercepting the requests and sinkholing the domains.&lt;/P&gt;&lt;P&gt;Since there isn't a straightforward "exception" button inside that specific DNS Trap profile menu, we need to implement an alternative workaround—either by Whitelisting the specific external IP addresses of the phishing infrastructure directly inside our exception rule&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 11:43:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277792#M10</guid>
      <dc:creator>VarunTP</dc:creator>
      <dc:date>2026-06-03T11:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277793#M11</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;did you take a look at this SK?&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk74060" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk74060&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 11:51:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277793#M11</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-06-03T11:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277795#M12</link>
      <description>&lt;P&gt;Thanks I have checked this and configured exception policy , But still the same&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 12:26:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277795#M12</guid>
      <dc:creator>VarunTP</dc:creator>
      <dc:date>2026-06-03T12:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277796#M13</link>
      <description>&lt;P&gt;Could you post the screenshots of the exception you created? What is the the test link used?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 12:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277796#M13</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-06-03T12:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277798#M14</link>
      <description>&lt;P&gt;C:\Users\&amp;gt;nslookup sharepointle.com&lt;BR /&gt;Server: x.x.org&lt;BR /&gt;Address: x.x.x.x&lt;/P&gt;&lt;P&gt;Non-authoritative answer:&lt;BR /&gt;DNS request timed out.&lt;BR /&gt;timeout was 2 seconds.&lt;BR /&gt;Name: sharepointle.com&lt;BR /&gt;Address: 62.0.58.94&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;C:\Users\&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 12:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277798#M14</guid>
      <dc:creator>VarunTP</dc:creator>
      <dc:date>2026-06-03T12:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277800#M15</link>
      <description>&lt;P&gt;Looks good, could you post the content of Phishing_Simulation and also paste, in text format, one log line of the dropped traffic?&lt;/P&gt;
&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 13:02:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277800#M15</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-06-03T13:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277801#M16</link>
      <description>&lt;P&gt;That's actually a different team is doing, which I don't have access, Can I uncheck the Activate DNS trap ? how much impact will be there , We do have defender for malware protection ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;This is what Firewall logs says when I click on the link&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Connection to DNS trap bogus IP. See sk74060 for more information. Access to site known to contain malware&lt;BR /&gt;&lt;BR /&gt;Time: 2026-06-01T12:14:38Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: bond0.151&lt;BR /&gt;Id: 31c63e26-93f0-43d1-6a1d-77ae0000000c&lt;BR /&gt;Sequencenum: 8&lt;BR /&gt;Threat Prevention Policy: INT-FW-SG1&lt;BR /&gt;Threat Prevention Policy Date:2026-05-29T10:13:01Z&lt;BR /&gt;Source: 192.168.x.x&lt;BR /&gt;Source Port: 51203&lt;BR /&gt;Destination Country: Israel&lt;BR /&gt;Destination: 62.0.58.94&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Session Identification Number:0x6a1d77ae,0xc,0x263ec631,0xd143f093&lt;BR /&gt;Protection Name: Phishing.TC.d942HVJn&lt;BR /&gt;Description: Connection to DNS trap bogus IP. See sk74060 for more information.&lt;BR /&gt;Confidence Level: High&lt;BR /&gt;Severity: Medium&lt;BR /&gt;Malware Action: Access to site known to contain malware&lt;BR /&gt;Protection Type: DNS Trap&lt;BR /&gt;Threat Prevention Rule ID: 5BD0A968-B0FD-4458-9356-0CFEC7BFB41A&lt;BR /&gt;Protection ID: 0043C0980&lt;BR /&gt;Log ID: 2&lt;BR /&gt;Scope: 192.168.x.x&lt;BR /&gt;Member Id: 1_2&lt;BR /&gt;Action: Prevent&lt;BR /&gt;Type: Log&lt;BR /&gt;Policy Name: INT-FW-SG1&lt;BR /&gt;Policy Management: OPCW-CHKPMGMT-01&lt;BR /&gt;Db Tag: {D31E9709-BC98-464E-B690-464BED5AE43E}&lt;BR /&gt;Policy Date: 2026-05-29T10:13:48Z&lt;BR /&gt;Blade: Anti-Virus&lt;BR /&gt;Origin: SG-CHKPFW-6200-1&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Threat&lt;BR /&gt;Resource: sharepointle.com&lt;BR /&gt;Marker: @A@@B@1780315156@C@666729&lt;BR /&gt;Log Server Origin: x.x.x.x&lt;BR /&gt;Origin Log Server IP: x.x.x.x&lt;BR /&gt;Index Time: 2026-06-02T01:40:45Z&lt;BR /&gt;Lastupdatetime: 1780316139000&lt;BR /&gt;Lastupdateseqnum: 8&lt;BR /&gt;Stored: true&lt;BR /&gt;Suppressed Logs: 6&lt;BR /&gt;Sent Bytes: 0&lt;BR /&gt;Received Bytes: 0&lt;BR /&gt;Interface: bond0.151&lt;BR /&gt;Description: 192.168.x.x performed access to site known to contain malware that was prevented with DNS Trap&lt;BR /&gt;Threat Profile: Optimized&lt;BR /&gt;Bytes (sent\received): 0 B \ 0 B&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 13:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277801#M16</guid>
      <dc:creator>VarunTP</dc:creator>
      <dc:date>2026-06-03T13:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277806#M17</link>
      <description>&lt;P&gt;Yes, you can disable th DNS malware trap, this is an additional feature that could help prevent malware connections by intervening and DNS query level, without the need to inspect traffic to identify malware; but if you have Anti-virus and anti-bot protection enabled you're protected in any case.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 13:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277806#M17</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-06-03T13:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Threat Prevention Exception Failing to Bypass Malware DNS Trap</title>
      <link>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277863#M19</link>
      <description>&lt;P&gt;Did you try the steps below to create the exception?&amp;nbsp; They are different than those in the ATRG for the DNS Trap feature:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182209" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk182209: How to add an exception rule if the DNS Trap feature drops legitimate traffic&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are also situations where Threat Prevention drops based solely on an IP address will occur for efficiency purposes on the SND within SecureXL, well before the Threat Prevention exceptions are ever consulted.&amp;nbsp; Not sure if this is the case for you, but as an example, TP exceptions will not affect IOC feed blocks unless special steps are taken:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk181044" target="_blank" rel="noopener"&gt;sk181044: ioc_feeds&amp;nbsp;blocks an IP address for which an&amp;nbsp;exception&amp;nbsp;was made&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 00:08:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Threat-Exposure-Management/Threat-Prevention-Exception-Failing-to-Bypass-Malware-DNS-Trap/m-p/277863#M19</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-06-05T00:08:04Z</dc:date>
    </item>
  </channel>
</rss>

