Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Kosin_Usuwanthi
Collaborator

Some DNS request not block by AV blade

I have disable DNS trap feature because I have no use internal DNS.

When I verify the log I see some request not block in the same protection name.

Please advice.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Keep in mind Anti-Bot is primarily a post-infection blade.
If a machine is looking up a potentially sketchy hostname via DNS, the machine could already be infected.
By default, we do classification in the background.
In the cases where there was a Prevent, the DNS name was in the gateway's local cache.
In the case where it was Detect, it wasn't immediately in the cache.

More discussion about this topic here:  https://community.checkpoint.com/t5/Logging-and-Reporting/Threat-Prevention-dns-trap-and-resource-ca...

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events