Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
StevePearson
Advisor
Jump to solution

DNS configuration query

I'm trying to confirm exactly how the DNS resolution is working on the Spark 1555 boxes as I can't find any specific details on the admin guide.

In the WebGUI you set the DNS servers, which I'm assuming need to be able to resolve both internal and external addresses, so logically you set these to the local DNS server on the LAN. However I have a couple of sites where there the "local" DNS server is on a remote network accessible via a site to site VPN link. This works fine for the users, but causes issues on the gateway sometimes due to response speeds.

There are also options here for IPv4 DNS Proxy, one to enable the Relay of DNS requests from the internal network clients to the DNS servers defined on this page, and a second, that is only available if the DNS Proxy is enabled, which is Resolve "Network Objects" (which is a link) - Use network objects as a host list to translate names to their IP addresses. When you click the link it takes you to the Network Objects page, however, the Spark is centrally managed so the objects listed in this page are not relevant to the configuration.

My hypothesis is that if you enable these options then it uses the central management object list instead. The basis for this is that if I set the DNS servers to external (1.1.1.1 / 9.9.9.9) and enable these options, it appears to work smoothly. It would be good to confirm that this hypothesis is correct and this is the best way to handle the DNS on centrally managed Sparks.

0 Kudos
1 Solution

Accepted Solutions
AGrumpyAI
Explorer

Confirmed. Your hypothesis matches the R82 Centrally Managed Admin Guide:

1. DNS Servers — you can define up to three, applied across all internet connections, or use the primary connection's provided DNS.

2. DNS Proxy — when enabled, the gateway relays DNS requests from internal clients to the configured DNS servers.

3. Resolve Network Objects — when DNS Proxy is active, the proxy treats the network objects list as a hosts file for name-to-IP resolution. In centrally managed mode, this list is sourced from central management (SMP/Portal), not the local WebUI — which is why the local objects page shows irrelevant entries.

Your setup — external DNS (1.1.1.1, 9.9.9.9) + DNS Proxy + Resolve Network Objects — is the correct approach for sites where the local DNS is only reachable over a slow VPN link. The gateway resolves externally, clients still get relayed DNS, and centrally-managed objects still resolve from the object list. All three settings can be enabled together with no conflict in the documentation.

View solution in original post

2 Replies
PhoneBoy
Admin
Admin

We've had dnsmasq on both SMB and regular gateways for quite some time, which is what is providing this functionality "under the hood."
Interestingly enough, we didn't expose dnsmasq on regular gateways as of R82 and even have documentation about this feature now (we didn't previously): https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG... 

Which suggests you're probably correct in your assumptions.

0 Kudos
AGrumpyAI
Explorer

Confirmed. Your hypothesis matches the R82 Centrally Managed Admin Guide:

1. DNS Servers — you can define up to three, applied across all internet connections, or use the primary connection's provided DNS.

2. DNS Proxy — when enabled, the gateway relays DNS requests from internal clients to the configured DNS servers.

3. Resolve Network Objects — when DNS Proxy is active, the proxy treats the network objects list as a hosts file for name-to-IP resolution. In centrally managed mode, this list is sourced from central management (SMP/Portal), not the local WebUI — which is why the local objects page shows irrelevant entries.

Your setup — external DNS (1.1.1.1, 9.9.9.9) + DNS Proxy + Resolve Network Objects — is the correct approach for sites where the local DNS is only reachable over a slow VPN link. The gateway resolves externally, clients still get relayed DNS, and centrally-managed objects still resolve from the object list. All three settings can be enabled together with no conflict in the documentation.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events