Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Some DNS request not block by AV blade

I have disable DNS trap feature because I have no use internal DNS.

When I verify the log I see some request not block in the same protection name.

Please advice.

0 Kudos
1 Reply
Highlighted
Admin
Admin

Re: Some DNS request not block by AV blade

Keep in mind Anti-Bot is primarily a post-infection blade.
If a machine is looking up a potentially sketchy hostname via DNS, the machine could already be infected.
By default, we do classification in the background.
In the cases where there was a Prevent, the DNS name was in the gateway's local cache.
In the case where it was Detect, it wasn't immediately in the cache.

More discussion about this topic here:  https://community.checkpoint.com/t5/Logging-and-Reporting/Threat-Prevention-dns-trap-and-resource-ca...