> Source: [sk109841](https://support.checkpoint.com/results/sk/sk109841)

# sk109841 - Security Gateway acting as proxy drops traffic with error "Proxy: DNS timeout/error: Connection was rejected due to DNS timeout or error"

| Property | Value |
|----------|-------|
| Solution ID | sk109841 |
| Date Created | 2016-01-27 |
| Last Modified | 2022-03-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * The Security Gateway, acting as proxy, drops traffic with the error "Proxy: DNS timeout/error: Connection was rejected due to DNS timeout or error."
* Some websites or resources are inaccessible.
* The Security Gateway can resolve the websites without issue.

## Cause

The Security Gateway makes a DNS request on behalf of the client. The response received from the server is larger than the 512 byte payload limit for DNS UDP responses.

The Security Gateway then makes a TCP DNS request. A response is received, but the security gateway takes no action with this information.

Shortly after that, the original DNS request times out and the drop is seen in SmartView Tracker / SmartLog.

## Solution

[Contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server and Security Gateways involved in the case.

<br />

**Hotfix installation instructions for Gaia OS:**

1. Hotfix has to be installed on ***Security Gateway / each cluster member.***

**Note**: In cluster environment, this procedure must be performed on all members of the cluster.

2. Transfer the hotfix package to the machine (into some directory, e.g., */some_path_to_fix/)*.

3. Unpack the hotfix package:

***\[Expert@HostName\]# cd /some_path_to_fix/***   
***\[Expert@HostName\]# tar -zxvf fw1_wrapper_\<HOTFIX_NAME\>.tgz***

4. Install the hotfix:

***\[Expert@HostName\]# ./fw1_wrapper_\<HOTFIX_NAME\>***

**Note**: The script will stop all of Check Point services (cpstop) - read the output on the screen.

5. Reboot the machine.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
