- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Dear mates,
I have an issue that applies to one user only. It has to be related to his endpoint specific, but I can't find out what it is.
When he connects to the IPSec client, even if the nslookup resolved the IP address of the domain name, it can't ping the web app or browser it.
The issue is fixed if entry is added to the /etc/hosts.
I run Wireshark to the endpoint and verify that DNS queries are sent to the IPsec tunnel interface.
Our GWs are R80.10 (Cluster) and IPSec client version E83.10 Build 986101816.
Thank you.
R80.10 is End of Support, highly recommend upgrading to a supported release.
We have got extension support from Checkpoint.
Hi there,
We started seeing this same behavior about a couple months ago. We are running R81 and Endpoint client R86.30 and 80 (tried to resolve but didn't). A bunch of users will be connected to the corporate VPN and all of a sudden then can no longer connect to an internal host via DNS all the while others are connecting to the same host successfully when they try. It may not be all the hosts that are unreachable. I suspect cache is influencing this.
at cmd, nslookup can resolved the name say target.corp.ca and identified the internal corporate DNS server as its source. Looking at the DNS cache does not show an entry for target.corp.ca. this was done thru Powershell using the "Get-DnsClientCache|findstr target.corp.ca" command. try ping target.corp.ca and no response. VPN tunnel is up and working with no issues from what we can tell. Now this gets stranger as a few different actions seems to restore services. 1) Wait a while and problem goes away. 2) disconnect from VPN and then reconnect. Some success. and 3) reboot laptop in this case. I have read in various articles that Win10 behaves in the fashion that it will blast all DNS requests out every interface that has a DNS server configured in the interface settings (either manually or auto). I have a case open with TAC and they are thinking that the Internet DNS servers are responding faster over the WIFI adapter than the replies from the Checkpoint VNA (Virtual Network adapter) which has the internal DNS servers defined. Changing interface metrics did not seem to work for us. Packet capturing is confirming that replies are coming from internals. I should mention that we are split-tunneling. Apparently if we weren't split tunnelled the problem goes away. Not practical in our age right now. Still somewhat at a loss like @SdanteMate We have been running VPN client for over 2 years now and only recently come across this behavior. We have moved our clients to new R81 firewall back this spring and only hearing this issue in the last couple months.
Cheers
Jacques
Check if the Endpoint Client getting IP address assigned by Office Mode.
Yes, it did.
Logically, if its one user, then certainly not issue on the gateway side. Maybe compare trac.config files.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY