- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Verify that DNS tunneling is being prevented in R8...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Verify that DNS tunneling is being prevented in R80.10
How do I verify that DNS Tunneling is being blocked in R80.10. I have found allot of good info if I was running R77.30 but it doesn't covert very well to R80.10.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The DNS Tunneling protection was introduced in R77.30 and, to the best of my knowledge, it should work the same in R80.x.
You need to make sure it is enabled in the relevant IPS profile.
It is NOT enabled by default in any of the default IPS profiles.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the quick reply and screen shots. After looking I do not even see DNS Tunneling as an option when I search under the IPS Protections. Is this something that is easy to correct or should I open a ticket with support?
Thanks
Matt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's a fairly old signature so if you've done it even once, it should be there.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes the last update was on 12/8/2019 Version 635198194.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like a TAC case is in order.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found it!! I believe that since we had it "Inactive" it would not show up in my search under IPS. So once I Went to IPS (1) > Protections(2) > IPS(3) then I could find it search(4) find it.
Thanks for the help.
