Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
uLsAlmighty
Explorer

DNS Reputation Logs

Hi All,

Recently, our group of companies merged their IT department.

Upon checking the logs of the other's company firewall I have noticed below:

fwlogs1.pngfwlogs2.png

Does this mean that the IP stated on the logs are infected? Or user simply just visit websites that has a lot of adware?

I have noticed also that the destination is Google DNS. Am I having a wrong impression here? Since the action is tag Detect, others are Prevent, I'm kinda worried here since our other firewall doesn't have this kind of logs (DNS reputation) even the DNS trap is On.

 

Version is R80.40

PS: I'm new in the security field, I'm currently having a hard time grasping all the information regarding fw logs and stuffs.

 

Hope you can help me clear things up.

0 Kudos
4 Replies
_Val_
Admin
Admin

Yes, this does not look good. You need to start cleaning the endpoints

0 Kudos
uLsAlmighty
Explorer

Hi Val,

What confuse me is that the destination is Google DNS. Also the action is mixed Detect and Prevent.fwlogs3.png

0 Kudos
_Val_
Admin
Admin

No confusion here, someone is trying to resolve a malicious domain via Google DNS server. the FW catches that and issues you a log.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Why is the DNS traffic confusing?

This log tells you why it was detect/allowed - did you review the SK listed in the description field?

https://support.checkpoint.com/results/sk/sk74120

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events