- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Some DNS request not block by AV blade
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some DNS request not block by AV blade
I have disable DNS trap feature because I have no use internal DNS.
When I verify the log I see some request not block in the same protection name.
Please advice.
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Keep in mind Anti-Bot is primarily a post-infection blade.
If a machine is looking up a potentially sketchy hostname via DNS, the machine could already be infected.
By default, we do classification in the background.
In the cases where there was a Prevent, the DNS name was in the gateway's local cache.
In the case where it was Detect, it wasn't immediately in the cache.
More discussion about this topic here: https://community.checkpoint.com/t5/Logging-and-Reporting/Threat-Prevention-dns-trap-and-resource-ca...
