> Source: [sk157493](https://support.checkpoint.com/results/sk/sk157493)

# sk157493 - Rules with domain object do not match properly after some time

| Property | Value |
|----------|-------|
| Solution ID | sk157493 |
| Date Created | 2019-07-03 |
| Last Modified | 2026-03-08 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Rules with domain objects do not match properly, causing traffic drop on the clean up rule.
* One of the Kernel tables related to the DNS such as dns_reverse_cache_tbl are reaching its limit (For dns_reverse_cache_tbl, the default is 25,000).
* The issue occurs for a few seconds and then resolved for some time until occur again.

## Cause

High number of domain objects causes traffic overload the DNS cache table.  
When the limit value is reached, the table gets reset to 0 and starts filling again.  
During the time of the reset, the GW loses all IP addresses associated with the domain objects causing traffic not to match the correct rules.  
The issue resolved after some seconds when the domain is resolved again.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
