- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
sk120558 does not apply - just FYI
problem is as self-explained by the screenshot. please have a look.
it is all fresh R80.40 all-in-one dual-stack infrastructure.
error is just an ALERT not BLOCK/DROP/DENY - just so you know 🙂
see the screen and tell me if you find any clues as I'm struggling to find any
1. DNS resolution works on v4 /both = fwd/rev
2. DNS resolution works on v6 /rev only! wonder why ...
ps. resolution from the gateway nslookup'ing or dig'ing - dig resolves ALL - nslookup resolves v6 only REV not FWD queries!
I think I found the bug chaps! see my screenshot.
Cheers
and 2 records to be specific @Ilya_Yusupov
hi guys
just to give you an update on the case:
1. please note that unless confirmed otherwise later on this week we have found the reasons and we're able to complete RCA 🙂
we found sort of intermitent solution for THESE issues on Alerts with Domain DNS errors.
[Expert@cp:0]# cpwd_admin list | grep wsdnsd
WSDNSD 12288 E 1 [14:01:13] 16/6/2020 Y wsdnsd
above process (when dns server changes occur on gaia (clish/webui) is not restarting itself but preserves old configuration before "save config". this process need to be kill -9 so it can re-start and start using new settings - then Alerts are gone untill you reboot the entire appliance / vm / gaia device.
I'm yet to confirm that when rebooting my core R80.40 lab device but if reboot brings "no Alerts" in logs then off we go we do know where is the issue.
the responsible blocke is called WSDNSD (Daemon) which hold configuration and only cpstop/cpstart/cprestart or reboot restarts its configuration (clish>show configuraiton dns).
I'm on investigation still but it all looks promising, hope you get my point and make your own testes in your labs confirming what we found yesteday
thanks to @iliyam and @mickey for their time and heads-up - R&D folks ROCKS! as alwasy - pleasure is all mine 🙂
Will do update you with any new development should reboot of the gaia change WSDNSD process stance, but so far so good and no new log Aleter entires are produced and issues on the latest R80.40 gaia (either StandAlone or SG distributed - just test tested today).
Cheers!
I had this with my 6600 ClusterXL running Check Point R80.40 and the cpstop/cpstart on each member cleared up the alerts. - Thanks Jerry!
In my case, it is suggested that the above error is only a follow-up error for the likes of:
Firewall - Protocol violation detected with protocol:(RTP), matched protocol sig_id:(1), violation sig_id:(10). (500)
Firewall - Protocol violation detected with protocol:(DNS-UDP), matched protocol sig_id:(16), violation sig_id:(17). (500)
Can you find these, too?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY