> Source: [sk185281](https://support.checkpoint.com/results/sk/sk185281)

# sk185281 - DNS Reputation Logs Show Gateway-Sourced Queries for a High-Risk Fully Qualified Domain Name Object

| Property | Value |
|----------|-------|
| Solution ID | sk185281 |
| Date Created | 2026-08-18 |
| Last Modified | 2026-09-01 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * DNS Reputation logs show DNS queries for a high-risk domain.

* The source IP address in the logs belongs to:

  * A Security Gateway

  * A Virtual System

  * An internal DNS server

* Packet captures and kernel debug data show the Security Gateway sending DNS queries to configured internal DNS servers.

* DNS Trap log entries appear. For example:

  ```
  DNS response was replaced with a DNS trap bogus IP
  ```

<!-- -->

* The original endpoint is not visible in the relevant logs.

* Analysis shows that an internal DNS server forwards the DNS request to an external DNS forwarder, and the forwarded connection triggers DNS Reputation inspection.

## Cause

A configured **Fully Qualified Domain Name (FQDN) object** matches the domain shown in the DNS Reputation logs.

The Security Gateway periodically resolves configured FQDN objects to maintain current IP address mappings. During this process, the Gateway sends DNS queries through its configured DNS servers. This behavior is expected.

Because the queried domain is categorized as high risk or malicious, DNS Reputation inspects and logs the DNS transaction. DNS Trap can replace the DNS response with a bogus IP address as part of the configured protection action.

If DNS forwarders are used, the original endpoint can become hidden, and the DNS transaction can appear to originate from the Security Gateway or an internal DNS server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
