Add the following to fwkern.conf in %fwbin%/boot/modules allow_dnssec_bit=1
There is a command line that you can run which will enable it dynamically, but you need the above to have it survive a firewall reboot. There's another issue I've run into with my Win2k3 servers and DNS. If they send a message outbound with Options on and the server on the other end doesn't support options it will return an error. However, DNS protocol enforcement drops this packet, and then the Win2k3 server never tries without options. I disabled DNS protocol inspection and then sniffed the traffic and the win2k3 server sent the DNS request with options, error returned, then win2k3 server resent the DNS request without options. Oh, and it should be noted that CheckPoint never logged the drop packet for the DNS failure. When you checked the logs, everything appeared as "accept" even though the firewall was imposing itself. At the moment the only solution we know of is to disable the options on the win2k3 server, but it would be nice if DNS protocol inspection would be state aware and allow the error packet to return to the DNS server so it could resubmit. Thanks, Derek O'Flynn Enterprise Information Security LSU Health Sciences Center [EMAIL PROTECTED] (504)568-6130 -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Dahl-Stamnes J�rn Sent: Tuesday, November 09, 2004 3:54 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1] SmartDefense and dnssec [EMAIL PROTECTED] Wrote: > I just updated my SmartDefense and started getting a lot of > 'Invalid DNS' > entries in Tracker (info field is "Attack info: Badly formed > DNS"). There > was a very noticeable adverse impact on external browsing and > downloads. > > Tech support tells me that the 'Badly formed DNS' message is caused by > dnssec and that by default, Fw-1 drops packets with dnssec > enabled. They > gave me a solution to disable the dsnssec check, which I did. > Browsing and > downloads are normal again. > > However, I would prefer to keep the dnssec check enabled. > Has anyone run > into this, and what other solutions did you implement in > order to leave the > default check enabled? My internal dns servers are Win2K. I have the same problems. Maybe you can share with me/other how you disabled the dnssec check? ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
