- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have a number of outbound Internet rules that we have to update regularly due to the destination IP changing:
Ie: URL thiswebsite.com was 1.2.3.4 and then the remote site IP changed to 7.8.9.10
Which means we have go update the thiswebsite.com firewall object that we have.
Is URL/FQDN natively supported/permitted without a license in R80+?
meaning - I can create a URL object call thiswebsite.com and when the IP changes at the remote side I have no need to update my rule(s)?
Yes, they are called Domain objects.
See https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Domain Objects are supported with the basic firewall license.
Yes, they are called Domain objects.
See https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Domain Objects are supported with the basic firewall license.
Phoneboy said it right, you just need basic license to use domain objects, no need for anything special.
We're using Domain Objects since couple of years without a problem (we have ~500 objects). Just pay attention that in some cases (like 1 in 100 or 1000) there might be a situation that your client would resolve the domain to IP address 1.2.3.4 while the CheckPoint GW would resolve that same domain to 1.3.4.2 IP address . To be honest, we never encountered that, or at leas I was not aware in those couple of years we're using it....
So in order not to face that, make sure that the DNS servers used by your clients, will be same as your CheckPoint Gateways, like some internal DNS servers....
One other thing, the object definition has an option to perform reverse DNS in order to assure that the IP resolves to the domain and vice-versa, still with cloud these days, the revers does not match.... so pay attention to that part.
Thank you,
Even in the 90s, Reverse DNS didn't always match up very well 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY