Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Harish_Sankaran
Explorer

DNS traffic is not passing through firewall

Hi Folks,

 

We are trying to do nslook-up from out side through URL.We want see the traffic from the URL.

a)Any end user NSLOOKUP request coming from internet hitting website,  It does not show logs in Firewall. Hence we are not able to detect connections as well as source IP address. We need detailed logs indicating NSLOOKUP request flow as well as Source IP details.

b)Is there any mode in Firewall for detailed log analysis. Currently limited logs are visible which may not be enough for any forensics if required.

 

 

0 Kudos
2 Replies
HeikoAnkenbrand
Champion Champion
Champion

Hi @Harish_Sankaran,

use the following cli commands
fw ctl zdebug drop | grep <source IP>
or
fw monitor -e "accept( host=<source IP>);"
to debug the traffic flow.

More to "fw monitor" could you found here:
R80.x - cheat sheet - fw monitor

 

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
0 Kudos
Maarten_Sjouw
Champion
Champion

I don't really see what you are trying to identify here. When I use nslookup to resolve a URL like:

nslookup www.google.com

all that will happen is that my machine will contact the configured DNS server and ask the question at which IP I can reach www.google.com, nslookup will not send any packet to www.google.com itself.

Extended logging can be set by enabling accounting.

Regards, Maarten
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events