<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS rewrite in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-rewrite/m-p/511847#M275</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am using DNS rewrite for a hosted service that we are connecting to, however, the global nature of this feature is causing me some problems now as we are connecting a network we do not manage to our firewall which causes routing to fail to the rewritten addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of the solutions I am considering is creating a new vsys on the firewall and using this for the rewrite, my reasoning for doing it this way is so that all other DNS traffic that does not go to this new vsys will not have their DNS entries rewritten.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I have a concern that moving the DNS rewrites to a separate vsys will not prevent DNS replies being rewritten in the old vsys ( due to the fact the documentation says the DNS rewrite occurs at the global level ). I understand that a separate vsys should for all intents and purposes run as a completely separate logical firewall but I am just a little concerned that this may be a scenario where it doesn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help here would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Aug 2022 14:33:08 GMT</pubDate>
    <dc:creator>MichaelWrigh</dc:creator>
    <dc:date>2022-08-15T14:33:08Z</dc:date>
    <item>
      <title>DNS rewrite</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-rewrite/m-p/511847#M275</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am using DNS rewrite for a hosted service that we are connecting to, however, the global nature of this feature is causing me some problems now as we are connecting a network we do not manage to our firewall which causes routing to fail to the rewritten addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One of the solutions I am considering is creating a new vsys on the firewall and using this for the rewrite, my reasoning for doing it this way is so that all other DNS traffic that does not go to this new vsys will not have their DNS entries rewritten.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I have a concern that moving the DNS rewrites to a separate vsys will not prevent DNS replies being rewritten in the old vsys ( due to the fact the documentation says the DNS rewrite occurs at the global level ). I understand that a separate vsys should for all intents and purposes run as a completely separate logical firewall but I am just a little concerned that this may be a scenario where it doesn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help here would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 14:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-rewrite/m-p/511847#M275</guid>
      <dc:creator>MichaelWrigh</dc:creator>
      <dc:date>2022-08-15T14:33:08Z</dc:date>
    </item>
  </channel>
</rss>

