- CheckMates
- :
- Products
- :
- General Topics
- :
- Internal DNS was flooded by bad TCP-based DNS from...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Internal DNS was flooded by bad TCP-based DNS from Check Point
Hello CheckMates,
we are having a strange behaviour affecting our internal DNS.
Basically Check Point servers are pointing to our internal DNS servers for name resolution (either public or internal). The internal DNS log is registering a lot of these message events (one every 2 minutes):
The DNS server received a bad TCP-based DNS message from xxx.xxx.xxx.xxx. The packet was rejected or ignored. The event data contains the DNS packet.
Where "xxx.xxx.xxx.xxx" is the IP address of Check Point servers.
This is the binary content associated to these events:
This events, of course, reports different binary data (the above is just an example).
Any advice ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could you please provide the version & jumbo take information of the gateway?
What blades are enabled on the gateway and are Domain Objects used in the access policy?
Refer also:
sk133313: Many DNS traffic logs after adding access rules with Domain Objects
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Chris_Atkinson,
R81 - Take 68 - Blades: fw vpn cvpn urlf av appi ips identityServer SSL_INSPECT anti_bot mon.
We have just two Domain Objects defined, nothing else.
Now the Check Point is pointing to internal DNS server (that, of course, is also able to resolve external names) so I suppose it is normal receiving DNS queries. The strangeness is that DNS server doesn't like (some of them) because: bad TCP-based DNS...
I could configure Check Point to point to external DNS servers (like Google) but then, it won't be able to resolve internal IP addresses (useful while surfing on SmartDashboard logs).
Bye,
Luca
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Where you change you dns server to exteranl DNS on the gaia or some where else? i have same issue but DNS is pointed to external DNS but i got the error on our internal DNS.
