smartlog too many logs:Non Compliant DNS

There are too many below logs in smartlog everyday.This caused a lot of confusion,I think these logs are useless.Does anyone else have this confusion? How to deal with this problem?Thanks!

When your evaluation results that these messages are useless then create an IPS exception from your internal networks for this specific IPS protection type.

I suggest you to investigate the root cause of these logs. The "Capture Packets" feature can be enabled for this Protection and it should help you to analyze the "problematic" traffic.

You can found the "Non Compliant DNS protection" under "Manage&Settings -> General -> Inspection Settings" section.

I advice to disable the capturing after your investigation will finish. 

I would agree that this does not appear to be an issue with Check Point but rather an issue with your environment, the firewalls are just reporting what they are seeing. You could create an exception to allow the traffic. It may be related to DNS Flag Day, similar symptoms described in sk112578.

Yes, I agree with Alejandro, that these drops can be related to sk112578 if your GW is R77.X. You can capture the dropped packets (as I described above) and take a look the "Z" and "ENDS version" fields. 

If you see, that packets which were dropped include non-zero parameters in these fields, means the issue is sk112578 related. If the GW is R77.30, the drops should disappear after installation of the Jumbo Hotfix Take_345

If the issue isn't related to the sk112578 I still suggest to investigate the drops and "problematic" DNS traffic.




