Sinkhole forges a response to a DNS query for domains that match the DNS
category configured for a sinkhole action to the specified
sinkhole server, to assist in identifying compromised hosts.
When the default sinkhole FQDN is used, the firewall sends the
CNAME record as a response to the client, with the expectation
that an internal DNS server will resolve the CNAME record,
allowing malicious communications from the client to the
configured sinkhole server to be logged and readily
identifiable. However, if clients are in networks without an
internal DNS server, or are using software or tools that cannot
be properly resolve a CNAME into an A record response, the DNS
request is dropped, resulting in incomplete traffic log details
that are crucial for threat analysis. In these instances, you
should use the following sinkhole IP address:
(198.135.184.22).