<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Different DNS Servers in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/different-dns-servers/m-p/1230053#M5929</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a lot of servers in production (PRD) and development (DVE) domain.&lt;/P&gt;
&lt;P&gt;Servers in PRD domain use our internal PRD-DNS-Server and those in DVE domain use our internal DVE-DNS-Server. Our PA-5400 series firewall is considered to be PRD domain and hence uses&amp;nbsp;internal PRD-DNS-Server to resolve FQDN objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now what happens is that intermittently, our DVE servers are unable to reach certain internet URLs. We found that, even though we have a policy on our firewall with fqdn object for that domain, at certain instances, the IP resolved by&amp;nbsp;PRD-DNS-Server and DVE-DNS-Server are different and hence the firewall blocks the connection.&lt;/P&gt;
&lt;P&gt;I have tried adjusting the FQDN refresh time on PA Firewall but it does not help because it depends on what IP is getting resolved at the instance of the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea on how to get around this problem? If I use&amp;nbsp;internal DVE-DNS-Server to resolve firewall objects then the production servers will have issues accessing the URLs.&lt;/P&gt;</description>
    <pubDate>Mon, 26 May 2025 06:07:43 GMT</pubDate>
    <dc:creator>PAFWNoob</dc:creator>
    <dc:date>2025-05-26T06:07:43Z</dc:date>
    <item>
      <title>Different DNS Servers</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/different-dns-servers/m-p/1230053#M5929</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a lot of servers in production (PRD) and development (DVE) domain.&lt;/P&gt;
&lt;P&gt;Servers in PRD domain use our internal PRD-DNS-Server and those in DVE domain use our internal DVE-DNS-Server. Our PA-5400 series firewall is considered to be PRD domain and hence uses&amp;nbsp;internal PRD-DNS-Server to resolve FQDN objects.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now what happens is that intermittently, our DVE servers are unable to reach certain internet URLs. We found that, even though we have a policy on our firewall with fqdn object for that domain, at certain instances, the IP resolved by&amp;nbsp;PRD-DNS-Server and DVE-DNS-Server are different and hence the firewall blocks the connection.&lt;/P&gt;
&lt;P&gt;I have tried adjusting the FQDN refresh time on PA Firewall but it does not help because it depends on what IP is getting resolved at the instance of the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea on how to get around this problem? If I use&amp;nbsp;internal DVE-DNS-Server to resolve firewall objects then the production servers will have issues accessing the URLs.&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 06:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/different-dns-servers/m-p/1230053#M5929</guid>
      <dc:creator>PAFWNoob</dc:creator>
      <dc:date>2025-05-26T06:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Different DNS Servers</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/different-dns-servers/m-p/1230087#M5935</link>
      <description>&lt;P&gt;Set up DNS Proxy on Palo.&lt;/P&gt;
&lt;P&gt;Add Palo DNS Proxy IP into Domain Controller Forwarder field in DNS setting (or DNAT outgoing port 53 traffic to DNS Proxy IP in Palo).&lt;/P&gt;
&lt;P&gt;This forces both domains to use Palo to resolve IPs and Palo will cache correct IP.&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 12:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/different-dns-servers/m-p/1230087#M5935</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-05-26T12:57:12Z</dc:date>
    </item>
  </channel>
</rss>

