Hello CheckMates,
we are having a strange behaviour affecting our internal DNS.
Basically Check Point servers are pointing to our internal DNS servers for name resolution (either public or internal). The internal DNS log is registering a lot of these message events (one every 2 minutes):
The DNS server received a bad TCP-based DNS message from xxx.xxx.xxx.xxx. The packet was rejected or ignored. The event data contains the DNS packet.
Where "xxx.xxx.xxx.xxx" is the IP address of Check Point servers.
This is the binary content associated to these events:
This events, of course, reports different binary data (the above is just an example).
Any advice ?