Add the following to fwkern.conf in %fwbin%/boot/modules

allow_dnssec_bit=1

There is a command line that you can run which will enable it dynamically,
but you need the above to have it survive a firewall reboot.

There's another issue I've run into with my Win2k3 servers and DNS.  If they
send a message outbound with Options on and the server on the other end
doesn't support options it will return an error.  However, DNS protocol
enforcement drops this packet, and then the Win2k3 server never tries
without options.  I disabled DNS protocol inspection and then sniffed the
traffic and the win2k3 server sent the DNS request with options, error
returned, then win2k3 server resent the DNS request without options.

Oh, and it should be noted that CheckPoint never logged the drop packet for
the DNS failure.  When you checked the logs, everything appeared as "accept"
even though the firewall was imposing itself.

At the moment the only solution we know of is to disable the options on the
win2k3 server, but it would be nice if DNS protocol inspection would be
state aware and allow the error packet to return to the DNS server so it
could resubmit.

Thanks,

Derek O'Flynn
Enterprise Information Security
LSU Health Sciences Center
[EMAIL PROTECTED] (504)568-6130

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of
Dahl-Stamnes J�rn
Sent: Tuesday, November 09, 2004 3:54 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] SmartDefense and dnssec

[EMAIL PROTECTED] Wrote:
> I just updated my SmartDefense and started getting a lot of
> 'Invalid DNS'
> entries in Tracker (info field is "Attack info: Badly formed
> DNS").  There
> was a very noticeable adverse impact on external browsing and
> downloads.
>
> Tech support tells me that the 'Badly formed DNS' message is caused by
> dnssec and that by default, Fw-1 drops packets with dnssec
> enabled.  They
> gave me a solution to disable the dsnssec check, which I did.
>  Browsing and
> downloads are normal again.
>
> However, I would prefer to keep the dnssec check enabled.
> Has anyone run
> into this, and what other solutions did you implement in
> order to leave the
> default check enabled?  My internal dns servers are Win2K.

I have the same problems. Maybe you can share with me/other how you disabled
the dnssec check?

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to