> Source: [sk183542](https://support.checkpoint.com/results/sk/sk183542)

# sk183542 - Endpoint logs are showing that vsmon.exe is attempting to reach out to malicious sites (Firewall - Threat Prevention Conflict)

| Property | Value |
|----------|-------|
| Solution ID | sk183542 |
| Date Created | 2025-06-09 |
| Last Modified | 2026-02-17 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |
| OS | Windows |

## Symptoms

- DNS resolution queries initiated by the Endpoint Firewall may be incorrectly flagged as malicious by other security components.

## Cause

1. The Endpoint Firewall supports rules based on URLs.
2. It functions at the IP address level and resolves these URLs to IP addresses by performing DNS lookups every hour. These lookups are not real connections to the malicious site.
3. Check Point and other security tools may flag these DNS queries as suspicious or malicious.
One typical example is a conflict between Firewall and Anti-Bot Blades.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
