- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Feature comparison - Newly Observed domain
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Feature comparison - Newly Observed domain
Hi There,
#askingforacustomer
Wondering what would be the closest to this fortigate (⚰️) feature below
Any thoughts on how checkpoint achieves something similar?
I know of course uncategorized Category but it's not exactly the same.
Description | This article explains how URLs in the 'Newly Observed Domain' classification are re-categorized. |
Scope | FortiGate 5.6 or above. |
Solution | A URL is detected as a 'Newly Observed Domain' if the domain name does not exist in the database and the URL is observed for the first time by the FDN server.
The URL will then remain in this category for 30 minutes during which it is scanned for malicious content.
If there is no malicious content found, the category for the URL changes to 'Not Rated'.
The duration depends on how popular the 'Unrated' websites are and how long the 'Unrated' queue is.
|
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I do not have a good answer for the current versions, hopefully someone else does, but it appears this feature or something similar will be available in R82. R82 New Features
Improved Threat Prevention Capabilities
- Added Advanced DNS capability to block DNS queries to newly created domains.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Personally, I would double check with your Sales engineer to verify.
Best,
Andy
