Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
unleashed
Explorer

issue with manual IOC

hi 

we configured a policy to block IOCs. IP objects and domain objects. we encounter a wired behavior that, randomly, Check Point blocks legitimate IP addresses. 

for example, we have added domain marl.com in the domain object to be blocked. Suddenly CP block google DNS 8.8.8.8, when we check the logs, it shows that 8.8.8.8 blocked because it's belonging to domain marl.com which is already added in IOC object. however, when we resolve the domain marl.com on the gateway it shows IP is 172.35.*. * 

any clue why this happened?

Thanks,

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The Occam's Razor answer is that it appears that, at least briefly, marl.com did resolve to 8.8.8.8.
Why that happened would likely require further investigation.

0 Kudos
the_rock
Legend
Legend

Might need TAC case to check this further.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events