Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
GDenisiak
Explorer

FQDN object

Hello

I have a issue with FQDN objects and couldn't find any info ho gateway behaves in my case.

I have a rule with FQDN objects as a DST and one of those objects i resolved in DNS into more than one IP address.

Example:

Name: amazon.com
Addresses: 205.251.242.103
176.32.98.166
176.32.103.205

In this case the rule is not catching connection and it is dropped in rule somewhere below.

When pattern is solved into only one address, then the rule catches traffic and all is going as suppose to.

Example:

Name: sky.de
Address: 104.81.219.149

 

Could anyone explain why is it happening and what is the actual mechanism behind that?

 

Br

GDenisiak

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

What precise version/JHF level?
As far as I know it should take all IPs the FQDN resolves to.

0 Kudos
GDenisiak
Explorer

This is Check Point CPinfo Build 914000196 for GAIA
[CPFC]
       HOTFIX_R80_30_GOGO_JHF_MAIN     Take:  196

[MGMT]
       No hotfixes..

[IDA]
       No hotfixes..

[FW1]
       HOTFIX_MAAS_TUNNEL_AUTOUPDATE
       HOTFIX_R80_30_GOGO_JHF_MAIN     Take:  196

FW1 build number:
This is Check Point's software version R80.30 - Build 175
kernel: R80.30 - Build 195

[SecurePlatform]
       HOTFIX_R80_30_GOGO_JHF_MAIN     Take:  196

[CPinfo]
       No hotfixes..

[PPACK]
       HOTFIX_R80_30_GOGO_JHF_MAIN     Take:  196

[DIAG]
       No hotfixes..

[CVPN]
       No hotfixes..

[CPUpdates]
       BUNDLE_MAAS_TUNNEL_AUTOUPDATE   Take:  30
       BUNDLE_INFRA_AUTOUPDATE Take:  34
       BUNDLE_DEP_INSTALLER_AUTOUPDATE Take:  18
       BUNDLE_R80_30_JUMBO_HF_MAIN_3_10_GW     Take:  196

[CPDepInst]
       No hotfixes..

[AutoUpdater]
       No hotfixes..

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events