> Source: [sk140612](https://support.checkpoint.com/results/sk/sk140612)

# sk140612 - "DNS timeout/error: Connection was rejected due to DNS timeout or error" error message when Users cannot browse to Internet 

| Property | Value |
|----------|-------|
| Solution ID | sk140612 |
| Date Created | 2018-11-19 |
| Last Modified | 2022-03-24 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Users cannot browse to internet and succeed only after refreshing the page
* "Proxy: DNS timeout/error: Connection was rejected due to DNS timeout or error" logs are shown in SmartLog
* WSDNSD debug shows " CDnsHandler::resolveIpCallback: dns response TIMEDOUT "

## Cause

When the gateway is configured as a non-transparent proxy, the DNS resolver opens one connection towards each configured DNS servers' */etc/resolv.conf* sending a number of queries per connection. When "delete on reply" on the DNS service is enabled, this will cause the connection to be deleted from the connections table once the first response from the DNS server is received. As a result, the rest of the responses are dropped by the cleanup rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
