> Source: [sk133313](https://support.checkpoint.com/results/sk/sk133313)

# sk133313 - Many DNS traffic logs after adding access rules with Domain Objects

| Property | Value |
|----------|-------|
| Solution ID | sk133313 |
| Date Created | 2018-08-02 |
| Last Modified | 2026-04-01 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Many DNS traffic logs after adding access rules with Domain Objects.
* SmartLog shows that the Security Gateway is generating a huge amount of DNS queries per day.
* High CPU utilization on log server.

## Cause

Starting from R80.10, to match a rule with FQDN Domain Object, the Security Gateway performs name resolution using direct DNS query. The resolved IP addresses are cached, and traffic to those IP addresses is matched on the rule using that FQDN object.

The timeout of the FQDN cache respects the TTL of the DNS. This may cause too many DNS query connections from the gateway to the DNS server. These are logged as implied rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
