cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Akamaitechnologies and FQDN firewall rulle

I have HIPs 8.0.0.4990 and I need to authorize access to a specific FQDN that is hosted on Akamai (meaning the IP address that resolves can change often).

I have noticed that in this case, the 1st time the rule is matched, a name lookup is performed and the traffic is allowed. Once the akamai IP address has been updated, the traffic is no longer allowed, since a new name lookup is not performed and hIPS caches the old IP.

This basically renders the FQDN functionality in the hIPS FW rules useless, unless there is a way to force it to perform a dns lookup with every connection to see if the IP changed.

Suggestions, please.

 

#hostintrusionprevention #epo 

5 Replies
McAfee Employee ktankink
McAfee Employee
Report Inappropriate Content
Message 2 of 6

Re: Akamaitechnologies and FQDN firewall rulle

@Jdtjordan1983 Please see KB71322.  The system must perform a new DNS query in order for the HIPS engine to cache the new IP address; HIPS does not do this DNS resolution on its own.

KB71322 - FQDN lookups for Host Intrusion Prevention 8.0
https://kc.mcafee.com/corporate/index?page=content&id=KB71322

Re: Akamaitechnologies and FQDN firewall rulle

Hello,

Thank you for the KB article, but it doesn't display how to enable DNS parsing with HIPS 8.0. Could you possibly tell me how to enable the DNS parsing within HIPS 8.0?

 

Thank you!

McAfee Employee ktankink
McAfee Employee
Report Inappropriate Content
Message 4 of 6

Re: Akamaitechnologies and FQDN firewall rulle

It's not something you can toggle off or on..  When the operating system performs DNS lookups, the HIPS engine will automatically cache the IP results.  The KB is showing a change from HIPS 7 to HIPS 8.  With HIPS 7, the HIPS Firesvc.exe service would actually perform the DNS lookups and that was changed with HIPS 8.0.

There are no options to configure with HIPS 8.0 in regards to DNS lookups/parsing; it's all done automatically via code.

Re: Akamaitechnologies and FQDN firewall rulle

Is it not possible to add a wildcard to the FQDN within HIPs? 

McAfee Employee ktankink
McAfee Employee
Report Inappropriate Content
Message 6 of 6

Re: Akamaitechnologies and FQDN firewall rulle

FQDN is defined as "fully qualified", so wildcards are not acceptable.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community