- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
I have the following queries regarding some of the limitations of Checkcpoint. Please clarify if you are aware of the solutions:
Thanks,
KNRao
I am not sure you can blok specific domain but together with IPS and Anti-not blades enabled you can use DNS Trap and the anti-bot uses dns reputation services that will automatically block access to known domains which are affected.
Basically my understanding of how it works. You you dont already have these blades enabled I would recommend it on perimeter firewall.
On clients use Sandblast Agent or better the full endpoint suite. Really strong products.
Best regards
Kim
It all depends whether the domain is already classified by Checkpoint as being DNS bad reputation. C&C and so on.If this is the case with the enabling of DNS trap SK74060 will block this communication. Checkpoint has added a lot features under the Threat Protection. URL filtering, Application control, DNS Trap, DNS reputation, IP reputations are really helpful and provide a multi layer protection.
In the case that a DNS entry is not classified by Checkpoint but you want to block DNS requests for a specific DNS entry I can suggest the following:
a) Follow the SK74060
b) Block all direct client DNS requests to the Internet.
c) Configure all your clients to use your Internal DNS server.
d) Add a DNS entry to the Host file of your DNS server with the Bogus IP.
In this way, your clients will be forced to use only your Internal DNS server and in the case that they query the DNS entry of your customised "malicious" domain you will have an exact log of who that client requested that log.
Having that log is very important in order to pinpoint which client is making this request.
Thanks,
Charris Lappas
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY