- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
A Check Point Firewall saw a DNS Request namesvrtwo.serveftp.com. The Check Point Firewall answered the (suspicious) DNS Request with the default DNS Trap IP. If you have an internal DNS Server, the Firewall cannot see or log the original Requester (the Client with a possible Bot) because the DNS Request comes form the internal DNS.
Then the client is sending a Request do namesvrtwo.serveftp.com (Resolved to the DNS Trap IP). This way you can find the Client infected by the Bot.
A Check Point Firewall saw a DNS Request namesvrtwo.serveftp.com. The Check Point Firewall answered the (suspicious) DNS Request with the default DNS Trap IP. If you have an internal DNS Server, the Firewall cannot see or log the original Requester (the Client with a possible Bot) because the DNS Request comes form the internal DNS.
Then the client is sending a Request do namesvrtwo.serveftp.com (Resolved to the DNS Trap IP). This way you can find the Client infected by the Bot.