<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicate DNS packets in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1241377#M6433</link>
    <description>&lt;P&gt;I'm encountering and issue where we are seeing duplicate DNS (UDP) packets coming out of the palo to the resolving server. S&lt;SPAN&gt;pecifically TXT records with multiple packets at the server (resolver) side vs. the normal request/response. At the client side we see the normal request response (2 packets).&amp;nbsp; The server side there are up to 6 packets for the same request.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Nov 2025 22:56:27 GMT</pubDate>
    <dc:creator>MattThomas</dc:creator>
    <dc:date>2025-11-06T22:56:27Z</dc:date>
    <item>
      <title>Duplicate DNS packets</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1241377#M6433</link>
      <description>&lt;P&gt;I'm encountering and issue where we are seeing duplicate DNS (UDP) packets coming out of the palo to the resolving server. S&lt;SPAN&gt;pecifically TXT records with multiple packets at the server (resolver) side vs. the normal request/response. At the client side we see the normal request response (2 packets).&amp;nbsp; The server side there are up to 6 packets for the same request.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 22:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1241377#M6433</guid>
      <dc:creator>MattThomas</dc:creator>
      <dc:date>2025-11-06T22:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate DNS packets</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1241428#M6434</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;that usually happens when DNS inspection or ALG is enabled and the firewall re-transmits or duplicates packets as part of its flow handling. Palo Alto can resend UDP requests if it doesn’t see a quick response or if session aging is aggressive.&lt;BR /&gt;&lt;BR /&gt;Check whether DNS Security or UDP session timeout is causing retries. You can also disable DNS proxy inspection on that policy to confirm if the duplication stops.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 12:37:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1241428#M6434</guid>
      <dc:creator>Elwin3</dc:creator>
      <dc:date>2025-11-07T12:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate DNS packets</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1242595#M6485</link>
      <description>&lt;P&gt;DNS proxy inspection is not enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;UDP session timeout is set for 60seconds&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2025 17:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/duplicate-dns-packets/m-p/1242595#M6485</guid>
      <dc:creator>MattThomas</dc:creator>
      <dc:date>2025-11-25T17:55:11Z</dc:date>
    </item>
  </channel>
</rss>

