- CheckMates
- :
- Products
- :
- General Topics
- :
- Check Point Can Detect & prevent Domain Fronting A...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check Point Can Detect & prevent Domain Fronting Attack technique
Dear Everyone,
Recently I noticed Domain Pronting attack technique is coming back, can Check Point Firewall prevent it? What features need to be enabled?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Btw, its enabled by default, but if you wish to change it, you can run below.
Andy
****************************
[Expert@R82:0]# fw ctl get int reject_domain_fronting_conns
reject_domain_fronting_conns = 0
[Expert@R82:0]# fw ctl set -f int reject_domain_fronting_conns 1
"fwkern.conf" was updated successfully
[Expert@R82:0]#
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear the_rock,
Thansk for your response, beside, Do we need any additional features to prevent this attack method?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Marcus,
Does not appear so. I also checked inspection settings, as well as IPS protections, could not find anything about it. Plus, does not mention anything extra in the sk either.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume this is part of Verified SNI support.
Doing anything related to SNI likely requires at least App Control (part of NGFW, NGTP, and NGTX licenses).
