- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- DNS Reputation Logs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS Reputation Logs
Hi All,
Recently, our group of companies merged their IT department.
Upon checking the logs of the other's company firewall I have noticed below:
Does this mean that the IP stated on the logs are infected? Or user simply just visit websites that has a lot of adware?
I have noticed also that the destination is Google DNS. Am I having a wrong impression here? Since the action is tag Detect, others are Prevent, I'm kinda worried here since our other firewall doesn't have this kind of logs (DNS reputation) even the DNS trap is On.
Version is R80.40
PS: I'm new in the security field, I'm currently having a hard time grasping all the information regarding fw logs and stuffs.
Hope you can help me clear things up.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, this does not look good. You need to start cleaning the endpoints
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Val,
What confuse me is that the destination is Google DNS. Also the action is mixed Detect and Prevent.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No confusion here, someone is trying to resolve a malicious domain via Google DNS server. the FW catches that and issues you a log.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why is the DNS traffic confusing?
This log tells you why it was detect/allowed - did you review the SK listed in the description field?
https://support.checkpoint.com/results/sk/sk74120
