<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS not resolving for a website in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571811#M2368</link>
    <description>&lt;P&gt;&amp;nbsp;That error means that the browser can not resolve an IP address for the name given... so the DNS is not working. If you do a nslookup for the name on a command line, what do you get? I am guess it is a "Non-existant domain" error. Does this extend to other internet names as well?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like you have DNS filtering in place somewhere that is blocking/filtering DNS responses (you can sinkhole DNS on the PaloAlto, but normally that returns an IP that directs to a blocked page or gets dropped, not return a not-resolved DNS error).&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2024 17:34:02 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2024-01-04T17:34:02Z</dc:date>
    <item>
      <title>DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571715#M2361</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been experiencing DNS resolution issue for one particular website on all the systems under our Palo Alto firewall network. However, it is working well on the systems under our Sophos network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At first, I checked the website category and found it falls under malware and gave an exception to it to be accessed on our network in the URL filtering, but no luck. Then, removed all the security profiles for the security rule that I am in and it didn't work either. In the meantime, I couldn't see any log in the traffic monitor. Then, I noticed the browser throwing this error "&lt;SPAN&gt;DNS_PROBE_FINISHED_NXDOMAIN"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It doesn't make sense, as it worked well on other systems that run through Sophos but not with any of the systems with Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help me with this and let me know if I am missing something.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Jerome&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 07:53:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571715#M2361</guid>
      <dc:creator>Jerome.j</dc:creator>
      <dc:date>2024-01-04T07:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571811#M2368</link>
      <description>&lt;P&gt;&amp;nbsp;That error means that the browser can not resolve an IP address for the name given... so the DNS is not working. If you do a nslookup for the name on a command line, what do you get? I am guess it is a "Non-existant domain" error. Does this extend to other internet names as well?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like you have DNS filtering in place somewhere that is blocking/filtering DNS responses (you can sinkhole DNS on the PaloAlto, but normally that returns an IP that directs to a blocked page or gets dropped, not return a not-resolved DNS error).&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 17:34:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571811#M2368</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-01-04T17:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571908#M2376</link>
      <description>&lt;P&gt;Hi Adrian,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't configure any DNS filtering in the firewall. Other names are getting resolved without issues.&lt;/P&gt;
&lt;P&gt;Then, I added a forward lookup zone for the website in our DNS server and added a host pointing to the site's public address. It worked fine and I let it be.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do I need to check anything on the firewall to access the website without that DNS host in the DNS server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Jerome&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 12:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571908#M2376</guid>
      <dc:creator>Jerome.j</dc:creator>
      <dc:date>2024-01-05T12:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571941#M2379</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317777"&gt;@Jerome.j&lt;/a&gt;&amp;nbsp; &amp;nbsp;I did request for site recategorize&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="list-unstyled query-result-ul"&gt;
&lt;LI&gt;&lt;STRONG&gt;URL&lt;/STRONG&gt;: &lt;A href="https://rentpro.rpa5.com" target="_blank"&gt;https://rentpro.rpa5.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Categories&lt;/STRONG&gt;: Real-Estate&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Risk Level&lt;/STRONG&gt;: Low-Risk&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Hope this helps you now&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 17:52:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571941#M2379</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-01-05T17:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571942#M2380</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317777"&gt;@Jerome.j&lt;/a&gt;&amp;nbsp; &amp;nbsp;Also I have no issues while accessing this website&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 17:58:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571942#M2380</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-01-05T17:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571943#M2381</link>
      <description>&lt;P&gt;Since you added a forward zone/resolution on your internal DNS server and it works, it sounds like your DNS server couldn't previously resolve that domain. Does your DNS server just forward requests to Google 8.8.8.8/etc. or does it actually work as a full recursive DNS server querying the SOA of the domain?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect the later, in which case your DNS server was probably trying to resolve the domain from the SOA but couldn't connect. That sounds like the PaloAlto was blocking the DNS server's requests out to the internet, not the end user's browser. I.e. your client browser is trying to go to "blog.example.com" so the following happens:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;1) The user types "blog.example.com" into the browser.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;2) The client machine sends a DNS lookup request for the FQDN to your DNS server. (client -&amp;gt; dns:53)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;3) The DNS server queries the root DNS servers and finds that the "example.com" SOA points to "ns.malware.test" (dns -&amp;gt; rootserver:53)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;4) The DNS server then tries to query "ns.malware.test" for the FQDN "blog.example.com" but is blocked by the PaloAlto do to the destination. (dns -X-&amp;gt; ns.malware.test:53)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;5) The DNS server is unable to resolve the domain so it sends a NXDOMAIN back to the client. (dns:53 -&amp;gt; client)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;6) The browser display a&amp;nbsp;&lt;SPAN&gt;DNS_PROBE_FINISHED_NXDOMAIN error to the user.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By putting a local forward zone into the DNS server, you have short-circuited steps #3-4 so the DNS server immediately returns the configured IP to the client in step #5 and the browser connects to that IP in step #6.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It is hard to guess at other people's PA configurations, but I would start looking in you logs for outbound connections from your DNS server to port 53 on internet hosts that may have been blocked (i.e. destination IP is in a blacklist, malicious IP EDL, country/region block, etc.). You can also use any one of many online tools to lookup the SOA of the domain you are having issues with, such as:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://mxtoolbox.com/SOALookup.aspx" target="_blank"&gt;https://mxtoolbox.com/SOALookup.aspx&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Once you know the SOA address, you can test whether connections from the DNS server to the SOA destination address it would be blocked by your filter rules: Policies -&amp;gt; Security -&amp;gt; Test Policy Match&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 18:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571943#M2381</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-01-05T18:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571998#M2383</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;. This is a much-needed one for me..&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2024 08:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/571998#M2383</guid>
      <dc:creator>Jerome.j</dc:creator>
      <dc:date>2024-01-06T08:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/572258#M2394</link>
      <description>&lt;P&gt;It is working fine for me now. Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 05:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/572258#M2394</guid>
      <dc:creator>Jerome.j</dc:creator>
      <dc:date>2024-01-09T05:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/572259#M2395</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184804"&gt;@Adrian_Jensen&lt;/a&gt;&amp;nbsp;I now get how it works and able to find out where it stuck.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 05:52:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/572259#M2395</guid>
      <dc:creator>Jerome.j</dc:creator>
      <dc:date>2024-01-09T05:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not resolving for a website</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/572353#M2399</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/317777"&gt;@Jerome.j&lt;/a&gt;&amp;nbsp; Thanks for letting us know.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 15:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-not-resolving-for-a-website/m-p/572353#M2399</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2024-01-09T15:06:48Z</dc:date>
    </item>
  </channel>
</rss>

