> Source: [sk178804](https://support.checkpoint.com/results/sk/sk178804)

# sk178804 - Malware DNS Trap protection in R81 and higher generates "Prevent" logs

| Property | Value |
|----------|-------|
| Solution ID | sk178804 |
| Date Created | 2022-04-26 |
| Last Modified | 2022-11-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- When the Malware DNS Trap is activated in the Threat Prevention profile (this is the default):

* Security Gateways **R80.40 and lower** generate this log:

  Blade - Anti-Virus

  Action - ***Detect***

  Description - DNS response was replaced with a DNS trap bogus IP. See sk74060 for more information.

  Protection Type - DNS Reputation
* Security Gateways **R81 and higher** generate this log:

  Blade - Anti-Virus

  Action - ***Prevent***

  Description - DNS response was replaced with a DNS trap bogus IP. See sk74060 for more information.

  Protection Type - DNS Reputation

## Cause

Because the Malware DNS trap actually prevents the malicious DNS requests, the action in the log record was changed from "Detect" to "Prevent" in Security Gateways starting from the R81 version.

## Solution

No fix is required. This behavior is by design.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
