Hello Team!
There is a need to block traffic from and to a resource by domain name.
We have created an access control rule with the FQDN object
The problem is that the resource is resolved to many ip addresses, and while Check Point sends a DNS query, half of the traffic is partially missed.
There is an option to increase TTL as described here https://support.checkpoint.com/results/sk/sk181215, but how effective will it be ?
Are there any other ways to completely deny traffic from a certain domain name and preferably with not too high load on the gateway ?
Also, we are interested in blocking by file resolution using blade ips, but I'm afraid that would be very resource intensive.