- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
hi,
I was asked today how FQDN objects work, especially when the client resolved the URL already in the LAN.
1. Assuming NON-FQDN mode
e.g.
- client resolves apps.apple.com from internal DNS server to IP address 95.1.1.1
- client forwards request to default router and then via firewall to internet
- The firewall has an NON-FQDN object apple.com which allows the traffic.
However, the firewall see the IP address and not the URL, correct?
Does the firewall always do a reverse DNS lookup to see if the destination IP is part of any FQDN object?
Default TTL = 60 seconds
The FQDN-A-Deeper-Dive-Customer.pdf did refer to older version.
https://community.checkpoint.com/t5/Management/Domain-Objects-FQDN-An-Unofficial-ATRG/m-p/40789/thre...
2. Assuming FQDN mode and destination www.apple.com
Default TTL = 3600 seconds
Does the firewall always do a reverse DNS lookup to see if the destination IP is part of any FQDN object?
Same question
Any idea?
Thanks; Regards
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY