Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MarcuzShinz
Contributor
Jump to solution

Check Point Can Detect & prevent Domain Fronting Attack technique

Dear Everyone,

 

Recently I noticed Domain Pronting attack technique is coming back, can Check Point Firewall prevent it? What features need to be enabled?

0 Kudos
1 Solution

Accepted Solutions
5 Replies
the_rock
Legend
Legend
the_rock
Legend
Legend

Btw, its enabled by default, but if you wish to change it, you can run below.

Andy

****************************

 

[Expert@R82:0]# fw ctl get int reject_domain_fronting_conns
reject_domain_fronting_conns = 0
[Expert@R82:0]# fw ctl set -f int reject_domain_fronting_conns 1
"fwkern.conf" was updated successfully
[Expert@R82:0]#

0 Kudos
MarcuzShinz
Contributor

Dear the_rock,

Thansk for your response, beside, Do we need any additional features to prevent this attack method?

0 Kudos
the_rock
Legend
Legend

Hi Marcus,

Does not appear so. I also checked inspection settings, as well as IPS protections, could not find anything about it. Plus, does not mention anything extra in the sk either.

Andy

0 Kudos
PhoneBoy
Admin
Admin

I assume this is part of Verified SNI support.
Doing anything related to SNI likely requires at least App Control (part of NGFW, NGTP, and NGTX licenses).

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events