Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cyberluke365
Contributor

Internal DNS was flooded by bad TCP-based DNS from Check Point

Hello CheckMates,

we are having a strange behaviour affecting our internal DNS.

Basically Check Point servers are pointing to our internal DNS servers for name resolution (either public or internal). The internal DNS log is registering a lot of these message events (one every 2 minutes):

The DNS server received a bad TCP-based DNS message from xxx.xxx.xxx.xxx. The packet was rejected or ignored. The event data contains the DNS packet.

Where "xxx.xxx.xxx.xxx" is the IP address of Check Point servers.

This is the binary content associated to these events:

CheckMates.png

This events, of course, reports different binary data (the above is just an example).

Any advice ?

 

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

Could you please provide the version & jumbo take information of the gateway?

What blades are enabled on the gateway and are Domain Objects used in the access policy?

 

Refer also:

sk133313: Many DNS traffic logs after adding access rules with Domain Objects

CCSM R77/R80/ELITE
0 Kudos
cyberluke365
Contributor

Hello @Chris_Atkinson,

R81 - Take 68 - Blades: fw vpn cvpn urlf av appi ips identityServer SSL_INSPECT anti_bot mon.

We have just two Domain Objects defined, nothing else.

Now the Check Point is pointing to internal DNS server (that, of course, is also able to resolve external names) so I suppose it is normal receiving DNS queries. The strangeness is that DNS server doesn't like (some of them) because: bad TCP-based DNS...

I could configure Check Point to point to external DNS servers (like Google) but then, it won't be able to resolve internal IP addresses (useful while surfing on SmartDashboard logs).

Bye,
Luca

0 Kudos
handiansudianto
Advisor

Hello,

Where you change you dns server to exteranl DNS on the gaia or some where else? i have same issue but DNS is pointed to external DNS but i got the error on our internal DNS.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events