- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have found an interesting way to rewrite DNS requests to other IP addresses.
This makes it possible to use the internal private addresses on the internal DNS server for the DNS requests.
External DNS queries that are requested via the Internet can be rewritten to official addresses on the firewall.
The ISP function can be used as a hack for this purpose.
If you activate and configure ISP Redundancy on the gateway, you have the option of rewriting DNS queries. This can be used to rewrite regular DNS queries to other IP addresses.
Example configuration:
1) Enable ISP on the gateway
2) Now select the “Primary/Backup” redundancy mode (see picture 1)
3) Now create an ISP link (that corresponds to your external interface in the direction to the Internet in my example “external_interface”.
4) Unfortunately, two interfaces must be defined, so you have to work with a placeholder interface for ISP2 link. Then create a link that only functions as a placeholder in my example “not_used”. Fictitious IP addresses can be used for the interface.
5) Now enabling “DNS Proxy”
6) In the next step, you can enter the DNS settings that you want to rewrite (red).
You can enter any address for the second ISP backup link (blue), as this is not used in my example.
Hello,
not sure if you could call it a "hack" ... it just the way it works i would say ...
overwrite everything with your manual configuration
maybe a dirty way to make split DNS when connecting via Client VPN. 🙂
Hi @Thomas_Eichelbu,
Hack or no hack.
Had used ISP in a customer project to do this.
It is the only way I know of to rewrite DNS requests on a gateway😊.
It is a pity that there is no DNS proxy that can be used to rewrite DNS queries. It was a feature request of me years ago.
ISP primary is not designed to rewrite DNS requests, but it can be used to do so, even if only one internet service provider is used.
Good point @HeikoAnkenbrand
Someone must have heard you (and others) as it's integrated into R82: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG...
The funny thing is that dnsmasq has been installed on Gaia since at least R77.20 though it was disabled.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY