Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
PobXL
Explorer

Unexplained DNS traffic, sent from wrp interface dummy object.

Hello Check Point Collective,

I'm trying to work out why I am seeing DNS traffic being sent to (3) internal AD servers coming from a dummy host object created for natting the IP address of the wrp interface on a VSX cluster.

Log entry below:

wcbc dns request edit.JPG

The traffic was getting flagged against Address Spoofing so we have added it to the Anti-spoofing group to remove the Detect from logs. But I would still like to understand why the traffic is being seen on this object.

R80.20SP / Take: 304
VSX running on Maestro.

I think the traffic may be due to the DNS configuration in GAIA pointing to these servers but I am not certain.

Any ideas?

PobXL
0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events