- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: issue with manual IOC
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
issue with manual IOC
hi
we configured a policy to block IOCs. IP objects and domain objects. we encounter a wired behavior that, randomly, Check Point blocks legitimate IP addresses.
for example, we have added domain marl.com in the domain object to be blocked. Suddenly CP block google DNS 8.8.8.8, when we check the logs, it shows that 8.8.8.8 blocked because it's belonging to domain marl.com which is already added in IOC object. however, when we resolve the domain marl.com on the gateway it shows IP is 172.35.*. *
any clue why this happened?
Thanks,
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The Occam's Razor answer is that it appears that, at least briefly, marl.com did resolve to 8.8.8.8.
Why that happened would likely require further investigation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Might need TAC case to check this further.
Andy
