cancel
Showing results for 
Search instead for 
Did you mean: 

Akamaitechnologies and FQDN firewall rulle

I have HIPs 8.0.0.4990 and I need to authorize access to a specific FQDN that is hosted on Akamai (meaning the IP address that resolves can change often).

I have noticed that in this case, the 1st time the rule is matched, a name lookup is performed and the traffic is allowed. Once the akamai IP address has been updated, the traffic is no longer allowed, since a new name lookup is not performed and hIPS caches the old IP.

This basically renders the FQDN functionality in the hIPS FW rules useless, unless there is a way to force it to perform a dns lookup with every connection to see if the IP changed.

Suggestions, please.

 

#hostintrusionprevention #epo 

5 Replies
Highlighted
ktankink McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 6

Re: Akamaitechnologies and FQDN firewall rulle

@Jdtjordan1983 Please see KB71322.  The system must perform a new DNS query in order for the HIPS engine to cache the new IP address; HIPS does not do this DNS resolution on its own.

KB71322 - FQDN lookups for Host Intrusion Prevention 8.0
https://kc.mcafee.com/corporate/index?page=content&id=KB71322

Re: Akamaitechnologies and FQDN firewall rulle

Hello,

Thank you for the KB article, but it doesn't display how to enable DNS parsing with HIPS 8.0. Could you possibly tell me how to enable the DNS parsing within HIPS 8.0?

 

Thank you!

ktankink McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 6

Re: Akamaitechnologies and FQDN firewall rulle

It's not something you can toggle off or on..  When the operating system performs DNS lookups, the HIPS engine will automatically cache the IP results.  The KB is showing a change from HIPS 7 to HIPS 8.  With HIPS 7, the HIPS Firesvc.exe service would actually perform the DNS lookups and that was changed with HIPS 8.0.

There are no options to configure with HIPS 8.0 in regards to DNS lookups/parsing; it's all done automatically via code.

Re: Akamaitechnologies and FQDN firewall rulle

Is it not possible to add a wildcard to the FQDN within HIPs? 

ktankink McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 6 of 6

Re: Akamaitechnologies and FQDN firewall rulle

FQDN is defined as "fully qualified", so wildcards are not acceptable.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community