Hi,
From the server I am able to resolve DNS queries and I can see the logs ok with SV Tracker, there were no errors before I applied the SD profile
Main Topics
Browse All TopicsHi,
I have enabled smart defense on a Checkpoint firewall NGX R65 using the default protection profile. I am getting a lot of errors abount Invalid DNS out of state DNS reply
Any ideas on how to fix this problem ?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
From sk26451
Attack Info: out-of-state DNS
This error message displays when DNS response matches no previous DNS request. This error could lead to DNS poisoning. out-of-state only happens when response came with no request, or when record of query in kernel table fails.
These packets are being dropped, but no actual long-term connectivity is lost, because packets are retransmitted without options. Remove DNS verification by changing protocol type of domain-udp service to none and reinstalling Security Policy. In SmartDefense setting under DNS setting, there is an option to change the Track to None.
Remove DNS verification by changing protocol type of domain-udp service to "none" and reinstalling Policy:
1. Close all GUI Clients (SmartDashboard).
2. Type cpstop.
3. Edit $FWDIR/conf/asm.C, and set property :fw_dns_verification (false).
4. Type cpstart.
5. Install Policy to make change effective.
This is normally on the smartcentre bud. The smartcentre complies all the policies and settings etc and then pushes them out to the firewall.
However, as the article says (albeit its hidden within the other entry) you can simple set the SD system not to log the drops.
"In SmartDefense setting under DNS setting, there is an option to change the Track to None."
Try this 1st bud, it may save you a stop/start
Smartdefence is one of those features that you cant fully turn off, but yes, its better to have it enabled as it can catch a lot of the DOS stuff, but the Gucci protocol inspection etc requires subs to obtain the signature updates etc.
In R70, the IPS feature is a lot better, as it really is an IPS product and not just some random protections applied to everything no matter what you do. With R70 you can specify exceptions etc thus reducing the false positive alerts etc. I would consider R70 as an upgrade option if you have the time and HW to support.
Business Accounts
Answer for Membership
by: deimarkPosted on 2009-08-18 at 04:07:50ID: 25121834
Double check that all DNS info is correct and that the smartcentre and firewall can get to it.
Can you also post a couple of the log entries you see? Double click the logs for the details.