<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 3260 Policy Rule losing DNS resolution to FQDN-defined site - 4.19.23 in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-3260-policy-rule-losing-dns-resolution-to-fqdn-defined-site-4/m-p/539498#M1167</link>
    <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The 10 minutes in your case is probably too long if it is resulting in loss of connectivity after a certain period&lt;/P&gt;
&lt;P&gt;since PAN-OS 9 the timeout can be reduced to seconds and that is probably what will fix the problem for you.&lt;/P&gt;
&lt;P&gt;see this kb article.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmq0CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmq0CAC&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 08:25:45 GMT</pubDate>
    <dc:creator>Y-alwaysMe</dc:creator>
    <dc:date>2023-04-20T08:25:45Z</dc:date>
    <item>
      <title>PA 3260 Policy Rule losing DNS resolution to FQDN-defined site - 4.19.23</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-3260-policy-rule-losing-dns-resolution-to-fqdn-defined-site-4/m-p/539452#M1165</link>
      <description>&lt;P&gt;We have a policy rule that contains an FQDN-defined website destination (yandr.wiredrive.com). When initially configured to pass traffic to required cloud-based resources, DNS resolution to the wiredrive.com site would happen regularly, usually after an hour or so. A Palo Alto knowledgebase article about the Fast-DNS caching used by cloud-based resources could be remediated by reducing the FQDN resolution time from the default from 30 minutes to 10 minutes. After the recommended change, the connection functioned normally for a 10-hour shift with no issues. After a few days we noticed that the connection would be lost overnight, and could only be resolved by "toggling" the policy rule, thereby renewing the connection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to configure PAN-OS policy rules to ensure uninterrupted connection to the cloud-based resource, without having to manually renew the connection?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fast-DNS Resolution Issues&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boQJCAY" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boQJCAY&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;How to change the FQDN Refresh Timers&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKbCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 01:38:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-3260-policy-rule-losing-dns-resolution-to-fqdn-defined-site-4/m-p/539452#M1165</guid>
      <dc:creator>Paul_Carpenter</dc:creator>
      <dc:date>2023-04-20T01:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: PA 3260 Policy Rule losing DNS resolution to FQDN-defined site - 4.19.23</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-3260-policy-rule-losing-dns-resolution-to-fqdn-defined-site-4/m-p/539498#M1167</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The 10 minutes in your case is probably too long if it is resulting in loss of connectivity after a certain period&lt;/P&gt;
&lt;P&gt;since PAN-OS 9 the timeout can be reduced to seconds and that is probably what will fix the problem for you.&lt;/P&gt;
&lt;P&gt;see this kb article.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmq0CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmq0CAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:25:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-3260-policy-rule-losing-dns-resolution-to-fqdn-defined-site-4/m-p/539498#M1167</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2023-04-20T08:25:45Z</dc:date>
    </item>
  </channel>
</rss>

