Firewall-1

[FW-1] Smartdefense DNS protection

Subject: [FW-1] Smartdefense DNS protection
From: Loge VK <logevk AT GMAIL DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Fri, 22 Jul 2005 19:42:30 -0700
Hi,

Anybody tried SmartDefense DNS protection in NGX?

It is not working in my setup. I enable DNS resorce records
enforcement and configured to allow ony two records of type mentioned.

But when I do tcp-dns using "ls -d <domainname>" via nslookup for a
server which is located across the firewall, I am able to get the
results and log shows tcp-dns service being allowed.

I even tried with allowing one RR, even then it is not working.....any
body tried this and got it working?

TIA,

-Loge

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>
  • [FW-1] Smartdefense DNS protection, Loge VK <=