<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS Failover Service in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-failover-service/m-p/998070#M5225</link>
    <description>&lt;P&gt;We are testing a 3rd party DNS failover service and they need a way to verify if our ISP is up.&amp;nbsp; My thought on this was to allow ping/icmp on our external nic from the vendor's public IP range, however that isn't an option.&amp;nbsp; We could allow http/https but I really hate the idea of opening the administrative access to the public, even if it is just their specific range of IP addresses.&amp;nbsp; We can specify any other TCP or UDP port for them to check but it has to be something the firewall NIC would respond to so the vendor knows it is alive.&amp;nbsp; Would maybe SNMP or Syslog traffic work?&amp;nbsp; Any thoughts or suggestions would be appreciated.&amp;nbsp; Thanks!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 14:04:18 GMT</pubDate>
    <dc:creator>B.Fisher</dc:creator>
    <dc:date>2024-12-12T14:04:18Z</dc:date>
    <item>
      <title>DNS Failover Service</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-failover-service/m-p/998070#M5225</link>
      <description>&lt;P&gt;We are testing a 3rd party DNS failover service and they need a way to verify if our ISP is up.&amp;nbsp; My thought on this was to allow ping/icmp on our external nic from the vendor's public IP range, however that isn't an option.&amp;nbsp; We could allow http/https but I really hate the idea of opening the administrative access to the public, even if it is just their specific range of IP addresses.&amp;nbsp; We can specify any other TCP or UDP port for them to check but it has to be something the firewall NIC would respond to so the vendor knows it is alive.&amp;nbsp; Would maybe SNMP or Syslog traffic work?&amp;nbsp; Any thoughts or suggestions would be appreciated.&amp;nbsp; Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 14:04:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dns-failover-service/m-p/998070#M5225</guid>
      <dc:creator>B.Fisher</dc:creator>
      <dc:date>2024-12-12T14:04:18Z</dc:date>
    </item>
  </channel>
</rss>

