- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Stop Logging DNS Reputation traffic
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Stop Logging DNS Reputation traffic
Is there a way to stop the Firewall Logging the DNS Reputations traffic.
We are using a SIEM System and we see alot of DNS Reputation traffic and was wondering if there is a way to stop the Firewall Logging this traffic between certain Source and Destination IP Addresses.
I have checked adding in a Exception in the Threat Prevention Policy but there is no option for DNS Reputation or DNS Trap.
We do not want to disable DNS Trap just stop logging the traffic between certain Source and Destination IP Addresses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you explored the filtering options with Log Exporter, or are you using another method for output of the logs to your SIEM?
Refer sk122323
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are wanting to stop logging this traffic on the Firewall, so we do not see these Logs in "Logs & Monitor"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is this what you might be looking for? I just picked random protection, but you get the idea...
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Something like that or even adding an Exception in the Threat Prevention Policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Instead if there a way to disable DNS Trap between certain IP Addresses?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to disable DNS Trap between certain IP Addresses?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to confirm you've configured DNS malware trap to be aware of your DNS servers so as to not flag those correct?
