- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Yesterday we had one customer that was experiencing no internet access for 2 hours. It was resolved by itself. Looking into the logs (afterwards) I found there were lots of requests to the proxy address but there was no requests going from the gateway to the internet.
DNS setting is for 3 different DNS servers, however it seems there was no other DNS server used but the first one in the list, is this something anyone else has seen/experienced?
Maybe DNS cache issue ?
There was a 2 hour outage, we found SK140612, where it is stated the proxy process sends requests to all configured DNS servers, plus that the first responding DNS servers answer is used and the other answers are discarded. So when the first responding server returns a bogus response, the rest is discarded and no proper responses will be received in time.
In the WSDNSD file we see a lot of these messages:
wsdns_monitor_init: registering active monitoring
wsdns_monitor_init: got process ID: 15958
wsdns_monitor_set_signal: called with signal=10
wsdns_monitor_init: registered monitor. RC: 0
wsdns_signals_init: daemon signals initiated successfully
wsdns_resolver_init: called
main: daemon entering loop...
Failed to open file 'fw_cmd.tmp': Too many open files
[wsdnsd 23719 4136200400]@GW1[17 Dec 14:14:57] wsdnsd: Mon Dec 17 14:14:57 2018
wsdns_monitor_init: registering active monitoring
wsdns_monitor_init: got process ID: 23719
wsdns_monitor_set_signal: called with signal=10
wsdns_monitor_init: registered monitor. RC: 0
wsdns_signals_init: daemon signals initiated successfully
wsdns_resolver_init: called
main: daemon entering loop...
Failed to open file 'fw_cmd.tmp': Too many open files
[wsdnsd 17889 4135504080]@GW1[17 Dec 17:04:46] wsdnsd: Mon Dec 17 17:04:46 2018
Weird thing is that at the exact same time of the last entry the internet access was restored.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY