> Source: [sk182088](https://support.checkpoint.com/results/sk/sk182088)

# sk182088 - The DNS Reputation protection drops DNS queries sent by a Standby cluster member

| Property | Value |
|----------|-------|
| Solution ID | sk182088 |
| Date Created | 2024-03-18 |
| Last Modified | 2025-01-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- SmartConsole shows this "Prevent" log for DNS query sent by a Standby cluster member:
> Origin - \<Name of Active Cluster Member object\>
>
> Blade - Anti-Virus
>
> Product Family - Threat
>
> Type - Log
>
> Action - Prevent
>
> Malware Action - DNS query for a site known to contain malware
>
> Protection Type - DNS Reputation
>
> Source - \<Name of Standby Cluster Member object\>
>
> Service - domain/udp (UDP/53)
>
> Vendor List - Check Point Threat Cloud

## Cause

The log shows the Standby cluster member as the source of this DNS traffic if the Access Control Policy contains Domain Objects (configured as FQDN) that were configured to prevent traffic to/from malicious URLs.

In such scenario, all cluster members performs DNS queries to resolve the Domain Objects configured. The cluster members send their DNS queries to all configured DNS servers. The cluster members keep the resolved IP addresses in their cache to match the traffic to rules faster.

In addition, such a log is generated when the "**wsdnsd** " process is restarted on the Standby cluster member (just this specific process, or a part of the "`cpstop ; cpstart`" commands).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
