Check Point версии R80.20 + Security Management, всё установлено на ESXi. В одной подсети есть DNS в той которой я и проверяю работу Check Point, все остальные 250 подсетей не используют не DHCP не DNS. NAT включил.
Вот такой лог без DNS на компьютере:Time: Today, 9:22:27
Interface Direction: inbound
Interface Name: eth2
Id: c0a80065-0100-00c0-5ded-e7fb00010000
Id Generated By Indexer: false
First: false
Sequencenum: 6
Source Zone: Internal
Destination Zone: External
Service ID: domain-udp
Source: LanTestKompXp (192.168.0.66)
Source Port: 1146
Destination: 8.8.8.8
Destination Port: 53
IP Protocol: UDP (17)
Xlate (NAT) Source IP: GW (10.0.0.2)
Xlate (NAT) Source Port: 59734
Xlate (NAT) Destination Port: 0
NAT Rule Number: 0
NAT Additional Rule Number: 0
Security Outzone: ExternalZone
Source Machine Name:
bambrxpvm@farmacia.by
Action: Accept
Type: Connection
Policy Name: Standard
Policy Management: SMS
Db Tag: {C2E75D2C-9970-9846-B3EC-EA750AE7923B}
Policy Date: Yesterday, 15:35:46
Blade: Firewall
Origin: GW
Service: domain-udp (UDP/53)
Product Family: Access
Logid: 0
Access Rule Name: Internet Acces
Access Rule Number: 6
Policy Rule UID: 07aa0ec0-62d1-4d27-aa00-da5d56a2d757
Layer Name: Network
Interface: eth2
Description: domain-udp Traffic Accepted from 192.168.0.66 to 8.8.8.8
Вот так всё работает когда включаю DNS:
Time: Today, 9:32:06
Interface Direction: inbound
Interface Name: eth2
Id: c0a80065-0100-00c0-5ded-ea3e00010002
Id Generated By Indexer: false
First: false
Sequencenum: 10
Source Zone: Internal
Destination Zone: External
Service ID: domain-udp
Source: LanTestKompXp (192.168.0.66)
Source Port: 1113
Destination: 10.0.0.100
Destination Port: 53
IP Protocol: UDP (17)
Xlate (NAT) Source IP: GW (10.0.0.2)
Xlate (NAT) Source Port: 51084
Xlate (NAT) Destination Port: 0
NAT Rule Number: 0
NAT Additional Rule Number: 0
Security Outzone: ExternalZone
Source Machine Name:
bambrxpvm@farmacia.by
Action: Accept
Type: Connection
Policy Name: Standard
Policy Management: SMS
Db Tag: {C2E75D2C-9970-9846-B3EC-EA750AE7923B}
Policy Date: Yesterday, 15:35:46
Blade: Firewall
Origin: GW
Service: domain-udp (UDP/53)
Product Family: Access
Logid: 0
Access Rule Name: Internet Acces
Access Rule Number: 6
Policy Rule UID: 07aa0ec0-62d1-4d27-aa00-da5d56a2d757
Layer Name: Network
Interface: eth2
Description: domain-udp Traffic Accepted from 192.168.0.66 to 10.0.0.100
Почему Check Point не раздаёт сам? Я в нём прописал DNS.