> Source: [sk155592](https://support.checkpoint.com/results/sk/sk155592)

# sk155592 - Sub-domains do not match a rule with a non-FQDN domain object

| Property | Value |
|----------|-------|
| Solution ID | sk155592 |
| Date Created | 2019-06-19 |
| Last Modified | 2022-11-06 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- * The firewall rule contains a non-FQDN domain object that should, but does not, match sub-domains according to [sk120633](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120633).

* When doing "`# nslookup <ip_address_of_subdomain>`" the user sees:

  ```
  
  ** server can't find "ip_address_of_subdomain".in-addr.arpa.: NXDOMAIN
  
  or
  
  *** "DNS_SERVER_NAME" can't find "ip_address_of_subdomain": Non-existent domain
  ```

  <br />

## Cause

"ip_address_of_subdomain" has no reverse lookup entry.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
