<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Service Route Configuration - DNS resolution seems to fail in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/service-route-configuration-dns-resolution-seems-to-fail/m-p/275017#M633</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently staging a PAN-VM (8.1.3 KVM) and have hit an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I've configured the interfaces, zones, routing (static default route) etc. correctly.&lt;/LI&gt;&lt;LI&gt;I've modified the service router configuration to use the Internet facing dataplane interface IP (i.e. customized and not use management interface). That is I allow DNS, NTP, Palo Alto updates to access the Internet via dataplane outside/untrust interface.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Under device--&amp;gt;services tab I have entered for DNS server settings (8.8.8.8) primary and 8.8.4.4 (secondary).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The issue:&lt;/P&gt;&lt;P&gt;I commit and immediately after I test pings from the CLI to: 8.8.8.8 sourcing from the outside interface and its sucessfully. I then ping google.com (either continuouly or specifying a ping count of 5) and it works 100%. However, after a few moments issuing new pings to google.com fail and I get the "ping: unknown host google.com". Further, I observe the PAN FW can no longer contact the licensing server or palo alto update server as it relies on successful DNS lookups. I turn my attention back to pings to the IP 8.8.8.8 and it doesn't skip a beat. 100% success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any further commits and immediately pings to google.com work again (continuous or count specified ping)&amp;nbsp; will yield 100% success. However, as soon as I kill the continuous pings (or use count specified ping) and wait a moment, the pings to domain names (google.com) fail again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2019 05:26:18 GMT</pubDate>
    <dc:creator>JohnRoberts</dc:creator>
    <dc:date>2019-07-05T05:26:18Z</dc:date>
    <item>
      <title>Service Route Configuration - DNS resolution seems to fail</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/service-route-configuration-dns-resolution-seems-to-fail/m-p/275017#M633</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently staging a PAN-VM (8.1.3 KVM) and have hit an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I've configured the interfaces, zones, routing (static default route) etc. correctly.&lt;/LI&gt;&lt;LI&gt;I've modified the service router configuration to use the Internet facing dataplane interface IP (i.e. customized and not use management interface). That is I allow DNS, NTP, Palo Alto updates to access the Internet via dataplane outside/untrust interface.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Under device--&amp;gt;services tab I have entered for DNS server settings (8.8.8.8) primary and 8.8.4.4 (secondary).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The issue:&lt;/P&gt;&lt;P&gt;I commit and immediately after I test pings from the CLI to: 8.8.8.8 sourcing from the outside interface and its sucessfully. I then ping google.com (either continuouly or specifying a ping count of 5) and it works 100%. However, after a few moments issuing new pings to google.com fail and I get the "ping: unknown host google.com". Further, I observe the PAN FW can no longer contact the licensing server or palo alto update server as it relies on successful DNS lookups. I turn my attention back to pings to the IP 8.8.8.8 and it doesn't skip a beat. 100% success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any further commits and immediately pings to google.com work again (continuous or count specified ping)&amp;nbsp; will yield 100% success. However, as soon as I kill the continuous pings (or use count specified ping) and wait a moment, the pings to domain names (google.com) fail again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 05:26:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/service-route-configuration-dns-resolution-seems-to-fail/m-p/275017#M633</guid>
      <dc:creator>JohnRoberts</dc:creator>
      <dc:date>2019-07-05T05:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Service Route Configuration - DNS resolution seems to fail</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/service-route-configuration-dns-resolution-seems-to-fail/m-p/276860#M636</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49828"&gt;@JohnRoberts&lt;/a&gt;: Is the issue still persistent?&lt;/P&gt;&lt;P&gt;I would suggest to have a log in the traffic log, if you got any dns response packets, while you experienced the issues.&lt;/P&gt;&lt;P&gt;Nonetheless, the current preferred PAN-OS release is 8.1.8.&lt;/P&gt;&lt;P&gt;If the issue is persitant after upgrading, please test, if other dns resolvers work better for your environment&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 16:41:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/service-route-configuration-dns-resolution-seems-to-fail/m-p/276860#M636</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-07-16T16:41:02Z</dc:date>
    </item>
  </channel>
</rss>

