- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: DNS Query going through implied rules
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS Query going through implied rules
Hi All,
Currently, we have a Checkpoint R81.10 Take 169 firewall. I'm observing a DNS query requests being sent to DNS servers via implied rules. Even the 'Accept Domain Name UDP Queries' option is unchecked DNS requests are still going through implied rules.
Can anyone guide or help us why such behavior is observed ??
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the source of the request?
Was the policy installed after the setting was unchecked?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The source is the CP gateway itself for url and IPS update. From the begning the setting was unchecked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is a separate implied rule that covers outbound traffic from the gateway itself.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Chris for your reply. So in that case is there a means of disabling/blocking only DNS requests originating from the gateway? What if I want to allow only explicitly permitted DNS servers?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Via explicit Access Policy rules, which will apply as long as the relevant Implied Rules are disabled or set to “Before Last.”
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I see the point Chris is making. If you can confirm that, would help us.
Andy
