- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Everyone,
Recently I noticed Domain Pronting attack technique is coming back, can Check Point Firewall prevent it? What features need to be enabled?
Btw, its enabled by default, but if you wish to change it, you can run below.
Andy
****************************
[Expert@R82:0]# fw ctl get int reject_domain_fronting_conns
reject_domain_fronting_conns = 0
[Expert@R82:0]# fw ctl set -f int reject_domain_fronting_conns 1
"fwkern.conf" was updated successfully
[Expert@R82:0]#
Dear the_rock,
Thansk for your response, beside, Do we need any additional features to prevent this attack method?
Hi Marcus,
Does not appear so. I also checked inspection settings, as well as IPS protections, could not find anything about it. Plus, does not mention anything extra in the sk either.
Andy
I assume this is part of Verified SNI support.
Doing anything related to SNI likely requires at least App Control (part of NGFW, NGTP, and NGTX licenses).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY