Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kaka
Explorer

Suspicious DNS Requests Made by DNS servers and Checkpoint Gateway

Hello Team,

As a request from IS team, we notice that checkpoint gateway frequently lookups to internal dns server its make by dns lookup behaviors. but with this behaviors the malicious domain that created on the domain object was also made and alerted to the abnormal activity on our DNS server.

Can we separate between public and private domain lookup on checkpoint? it's meant that if private domain can lookup to internal dns but if public domain query external DNs.

 

Toura

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

DNS Forwarding is supported in R82.
This relies on dnsmasq, which is actually installed in Gaia OS releases as far back as at least R77.20, but is not enabled or used.
Having said that, I wrote a procedure years ago to enable and configure it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events