- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Just wondering if anyone else has noticed if you are using domain objects (new type)
I noticed high amount of Block / Alert logs on the gateway complaining it was not able to resolve DNS even though DNS is responding OK.

When I run tcpdump I noticed that firewall sends DNS requests for each domain object in big batches (multiple requests for the same name within 100ms). So there are hundreds of DNS requests spat out every 30 secs for 20 domain objects so I'm not surprised if some are not answered.

I have not raised SR yet - just wondering if it's "known" issue? We are on take 121.
There is one SK that matches symptoms but that should have been fixed in take 42
Hi,
This is a known issue, solved in R80.10 JHF T142.
It will happen when using large amount of domain objects in policy.
Please contact support (& CFG) if you need the fix on top of earlier JHF take.
Thanks,
Meital
Hi, it seems RAD cache is not okay. Please do open a support ticket for proper diagnostics
Are you using None-FQDN mode (sk120633) ?
It's the R80.10 FQDN type objects. Using old makes no sense ![]()
I second that 😉
SR is still under investigation but someone else is bored, you may check if your gateway is sending malformed truncated DNS requests using TCP - has all domain objects included multiple times but most importantly packet format is wrong. Our DNS just replies as malformed packet, no results. Seems to match Blocked traffic in logs

Hi,
This is a known issue, solved in R80.10 JHF T142.
It will happen when using large amount of domain objects in policy.
Please contact support (& CFG) if you need the fix on top of earlier JHF take.
Thanks,
Meital
Thanks heaps Meital! Strangely enough case engineer just asked me for more debugs and logs instead of suggesting this...
Haha - I didn't realise that you were from R&D .. Just had a call from case engineer. All good - we'll try one cluster in next couple of days! Thanks again!
One last update - finally we rolled out take 142 last night in production: 2 VSX clusters and one non-VSX. All looking great so far, all block logs gone!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 16 | |
| 8 | |
| 7 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 2 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY