<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Submitting DNS block without blocking the IP in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/145982#M156</link>
    <description>&lt;P&gt;I'm looking to submit a FQDN block where I don't ever block the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've reviewed this article on blocking FQDN's but can't seem to figure out how to ignore the IP. We assign fake ip addresses to known malicius sites, and need the HTTP, HTTPS, SSH, etc traffic to route back to us, but the block on the FQDN is also blocking the IP once the lookup is processed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Mar 2017 18:11:13 GMT</pubDate>
    <dc:creator>dlevenden</dc:creator>
    <dc:date>2017-03-03T18:11:13Z</dc:date>
    <item>
      <title>Submitting DNS block without blocking the IP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/145982#M156</link>
      <description>&lt;P&gt;I'm looking to submit a FQDN block where I don't ever block the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've reviewed this article on blocking FQDN's but can't seem to figure out how to ignore the IP. We assign fake ip addresses to known malicius sites, and need the HTTP, HTTPS, SSH, etc traffic to route back to us, but the block on the FQDN is also blocking the IP once the lookup is processed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-and-Test-FQDN-Objects/ta-p/61903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 18:11:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/145982#M156</guid>
      <dc:creator>dlevenden</dc:creator>
      <dc:date>2017-03-03T18:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Submitting DNS block without blocking the IP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/146242#M158</link>
      <description>&lt;P&gt;I'm not sure I understand your problem. You mean you have a blocking rule with the FQDN as the destination address? If you want to reroute the traffic to some identified malicious websites, why do you have a blocking rule in the first place?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 20:57:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/146242#M158</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2017-03-06T20:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Submitting DNS block without blocking the IP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/146529#M162</link>
      <description>&lt;P&gt;great question. We offer a service to a customer that blocks on a paloAlto system at their end, which we're fine with them blocking the FQDN, but we need to not block the IP at the same time to allow other traffic to make it through if the name/domain&amp;nbsp;isn't blocked on the customer side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 21:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/146529#M162</guid>
      <dc:creator>dlevenden</dc:creator>
      <dc:date>2017-03-07T21:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Submitting DNS block without blocking the IP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/154471#M170</link>
      <description>&lt;P&gt;Check dns-req-section in page 19 of this document:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Creating-Custom-Application-and-Threat-Signatures/ta-p/58569" target="_blank"&gt;Creating Custom Application and Threat Signatures&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's an example for FQDN &lt;A href="http://www.thebayareagamers.com" target="_blank"&gt;www.thebayareagamers.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also add an EDL of type "Domain" and point it to a web-server that contains the list of domains you want to block.&lt;/P&gt;
&lt;P&gt;See:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/PANOS71Articles/article-id/10" target="_blank"&gt;https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/PANOS71Articles/article-id/10&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 17:24:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/submitting-dns-block-without-blocking-the-ip/m-p/154471#M170</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-05-10T17:24:43Z</dc:date>
    </item>
  </channel>
</rss>

