- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- DNS bad TCP
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS bad TCP
Hello,
We pointing DNS IP address for our VPN Pool IP to internal windows DNS server. When i check log on the windows dns server i got many warning 'The DNS server received a bad TCP-based DNS message from 10.103.254.6. The packet was rejected or ignored. The event data contains the DNS packet.'
IP 10.103.254.6 is our checkpoint.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Has also been dicussed her without a solution: Internal DNS was flooded by bad TCP-based DNS from Check Point
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
on the sk 133313 there are 2 solution :
1. disable 'Log implied rules', i check this already disabled.
2. Change rad_kernel_domain_cache_refresh_interval and rad_kernel_domain_cache_ip_success_lookup_timeout. What value is recommended for both parameters?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How does your version/JHF compare to that listed in the previous similar threads?
I see two SR's with similar symptoms but the cause was undetermined in each.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i using version 81.10 with JHF 87
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would contact TAC about this, honestly. I checked support site and literally only things that show up are community posts and specifically one that @G_W_Albrecht pointed to.
Andy
