Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MarcuzShinz
Contributor
Contributor
Jump to solution

Check Point Can Detect & prevent Domain Fronting Attack technique

Dear Everyone,

 

Recently I noticed Domain Pronting attack technique is coming back, can Check Point Firewall prevent it? What features need to be enabled?

5 Replies
the_rock
Legend
Legend

Btw, its enabled by default, but if you wish to change it, you can run below.

Andy

****************************

 

[Expert@R82:0]# fw ctl get int reject_domain_fronting_conns
reject_domain_fronting_conns = 0
[Expert@R82:0]# fw ctl set -f int reject_domain_fronting_conns 1
"fwkern.conf" was updated successfully
[Expert@R82:0]#

MarcuzShinz
Contributor
Contributor

Dear the_rock,

Thansk for your response, beside, Do we need any additional features to prevent this attack method?

the_rock
Legend
Legend

Hi Marcus,

Does not appear so. I also checked inspection settings, as well as IPS protections, could not find anything about it. Plus, does not mention anything extra in the sk either.

Andy

PhoneBoy
Admin
Admin

I assume this is part of Verified SNI support.
Doing anything related to SNI likely requires at least App Control (part of NGFW, NGTP, and NGTX licenses).

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events