<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting traffic being blocked based on IP - FQDN rules in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543841#M1359</link>
    <description>&lt;P&gt;Thanks Adrian, so far that's the conclusion I came to as well, which is kind of limited for the product in my opinion that's a lot of leg work for something that can happen regularly.&lt;/P&gt;</description>
    <pubDate>Mon, 29 May 2023 19:58:38 GMT</pubDate>
    <dc:creator>Luc_Desaulniers</dc:creator>
    <dc:date>2023-05-29T19:58:38Z</dc:date>
    <item>
      <title>Troubleshooting traffic being blocked based on IP - FQDN rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543548#M1342</link>
      <description>&lt;P&gt;Trying to find which FQDN object in my FQDN cache resolves to an IP.&lt;/P&gt;
&lt;P&gt;show dns-proxy fqdn all | match &amp;lt;ip&amp;gt; shows me that it's in my cache, but doesn't show FQDN object name, so it doesn't really help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure if there's a way to dump this to a file or something or a more straight forward way to do this.&lt;/P&gt;
&lt;P&gt;Any insights is appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;LD&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 19:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543548#M1342</guid>
      <dc:creator>Luc_Desaulniers</dc:creator>
      <dc:date>2023-05-26T19:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting traffic being blocked based on IP - FQDN rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543759#M1349</link>
      <description>&lt;P&gt;"show dns-cache fqdn all" shows you all the address objects and their resolved IPs. Unfortunately, as you discovered, the object name and resolved addresses are on sequential lines... So if you use a "match" operator you only match the IP line, not the preceding object name line. Even more unfortunately, address objects are not displayed in any discernable order.. .so its even harder to find.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only "easy" way I've found to do it is to do a "show dns-cache fqdn all" and paste the output into notepad, then find the IP from there and look at the preceding address object name. Alternatively you could probably query all the address objects via the API and filter/return a match, but you would need to write a script in your language of choice to do that.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 02:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543759#M1349</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2023-05-29T02:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting traffic being blocked based on IP - FQDN rules</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543841#M1359</link>
      <description>&lt;P&gt;Thanks Adrian, so far that's the conclusion I came to as well, which is kind of limited for the product in my opinion that's a lot of leg work for something that can happen regularly.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 19:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/troubleshooting-traffic-being-blocked-based-on-ip-fqdn-rules/m-p/543841#M1359</guid>
      <dc:creator>Luc_Desaulniers</dc:creator>
      <dc:date>2023-05-29T19:58:38Z</dc:date>
    </item>
  </channel>
</rss>

