> Source: [sk184635](https://support.checkpoint.com/results/sk/sk184635)

# sk184635 - Security Gateway sends DNS queries to a DNS server that is currently not configured

| Property | Value |
|----------|-------|
| Solution ID | sk184635 |
| Date Created | 2026-03-16 |
| Last Modified | 2026-03-26 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |

## Symptoms

- * Traffic captures show the Security Gateway sending DNS queries to a DNS server that was configured previously but is no longer present in the current DNS or proxy configuration.

* In Gaia clish, `show dns` does not show the unexpected DNS server.

* WSDNSD debugging (as described in [sk97638](https://support.checkpoint.com/results/sk/sk97638)) indicates DNS requests are sent to the older DNS server.

## Cause

The WSDNSD daemon (Web Services DNS Daemon) handles several DNS-related operations on the Security Gateway, including resolving domain objects (see [sk97638](https://support.checkpoint.com/results/sk/sk97638)).  

WSDNSD loads the DNS server configuration only at process startup. If the DNS server configuration changes while WSDNSD is already running, the process continues to use the previously loaded DNS servers until it restarts.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
