- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
sk131852 makes note when using updatable objects that:
“To work well, the DNS set on the gateways must be the same as that used by the endpoints. Otherwise, the IP-domain mapping will not match.”
We can confirm when the Checkpoint gateways are on different DNS from the endpoints, use of updatable objects can break.
In our environment all endpoints point to a service like Cisco Umbrella. The Checkpoint gateways points to the ISP DNS.
We had concerns about pointing the gateways to a DNS security service because:
We know updatable objects can break if the gateways and endpoints are not resolving to the same source. What can break if they are (and the source is a DNS security service like OpenDNS)?
Hey,
On our whole environment we use Umbrella DNS and we didn't had any issues with CheckPoint FQDN objects.
Whatever Umbrella DNS doesn't catch, CheckPoint will do.
Still CheckPoint will see the DNS requests if the GW is in path for all clients - not sure how you are set.
Thank you,
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY