Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nadezhda
Participant

Blocking a resource by domain name

Hello Team!

There is a need to block traffic from and to a resource by domain name.
We have created an access control rule with the FQDN object
The problem is that the resource is resolved to many ip addresses, and while Check Point sends a DNS query, half of the traffic is partially missed.

There is an option to increase TTL  as described here https://support.checkpoint.com/results/sk/sk181215, but how effective will it be ?

Are there any other ways to completely deny traffic from a certain domain name and preferably with not too high load on the gateway ?

Also, we are interested in blocking by file resolution using blade ips, but I'm afraid that would be very resource intensive.

 

0 Kudos
3 Replies
G_W_Albrecht
Legend
Legend

0 Kudos
PhoneBoy
Admin
Admin

The gateway must either see the DNS requests made by the client (Passive DNS Learning in R80.40+) OR use the same DNS servers the client does.
Otherwise, there will be differences in enforcement, as you are observing.

What do you mean by "blocking by file resolution using IPS" exactly?

0 Kudos
the_rock
Legend
Legend

There were few posts about this in the past and this is not sadly the optimal way of doing it. Should be done with urlf blade, as well as when https inspection is enabled. You can create domain object and use it in the rule, but in my experience, that may work randomly, as the fqdn itself may end up resolving to different IPs and they may change constantly.

Best regards,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events