hi
we configured a policy to block IOCs. IP objects and domain objects. we encounter a wired behavior that, randomly, Check Point blocks legitimate IP addresses.
for example, we have added domain marl.com in the domain object to be blocked. Suddenly CP block google DNS 8.8.8.8, when we check the logs, it shows that 8.8.8.8 blocked because it's belonging to domain marl.com which is already added in IOC object. however, when we resolve the domain marl.com on the gateway it shows IP is 172.35.*. *
any clue why this happened?
Thanks,