| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I have some Windows servers trying to register their DNS A records with a Windows DNS server and SD is rejecting these attempts with a "DNS data is too long" error. I did some Ethernet sniffing and it looks like TKEY queries are being blocked. I'm running R61, and according to Checkpoint they've supported TKEY since R60 HFA 01. But the error R60 HFA 01 fixed was an invalid RR type, not a data length issue. Has anyone else seen this and know any workarounds? |
| |||
| This article sk31051 titled " Enabling DNS TCP protocol enforcement" mentions a kernel parameter that can be changed to disable this check. It specifically mentions your "DNS data is too long" error message although it pertains to zone transfers. You might want to try its suggested fix. Or maybe there's a way to turn off DNS TCP checks in the GUI? Since Check Point doesn't make its KB available without an appropriate subscription, I don't think it would be permissible to put the contents of the article here. I'd open a case with Check Point as well. Take care, Ray |
| |||
| I actually read this article as well... The way I understood it, it only applies to traffic between "Defined DNS servers" whereas the problem I'm seeing is between a DNS server and a lot of Windows clients. I worked around this by turning off DNS "TCP protocol enforcement" in the GUI. I just find it hard to believe that I'm the only person having this problem. |
| |||
| Hi, I have the same problem, DNS data is too long between windows servers and Windows DNS server (only for domain-tcp service). But i uncheck in Smart Defense DNS section: TCP protocol enforcement and stiil have the error DNS data is too long. Then i uncheck UDP protocol enforcement too (just in case) but still have the error. I have the Smart defence version 591070510 Thanks in advance |
![]() |
| Thread Tools | |
| Display Modes | |
| |