<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why Management interface do query instead of DNS-Proxy Interface in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-management-interface-do-query-instead-of-dns-proxy-interface/m-p/531454#M913</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I configured DNS proxy Interface e1/1 - 192.168.29.245 to clientless vpn.&lt;/P&gt;
&lt;P&gt;DNS-Proxy resolves as,&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;General browsing resolves with DNS 8.8.8.8 and 1.1.1.1&lt;/LI&gt;
&lt;LI&gt;Tutelartechlabs.com resolves with DNS 1.1.1.2 and 4.4.4.4&lt;/LI&gt;
&lt;LI&gt;Amazon.forest.in (internal-application) resolves with DNS 172.30.30.31&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48043iE7EB78D86C1B0679/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC1.jpg" alt="LC1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC2.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48044iB234722EADAD2D88/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC2.jpg" alt="LC2.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC3.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48045iCD023940258CCF48/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC3.jpg" alt="LC3.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC4.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48046iABF7CA957EB490F5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC4.jpg" alt="LC4.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;DNS-Proxy interface is the interface that act as a proxy and queries for dataplane traffic instead of management interface setup--&amp;gt;service--&amp;gt;DNS.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;so the question is why my &lt;STRONG&gt;management interface 192.168.29.250&amp;nbsp;&lt;/STRONG&gt;queries for a&lt;STRONG&gt;mazon.forest.in&lt;/STRONG&gt; to the DNS server when the application is accessed by a user in clientless-vpn&amp;nbsp; &lt;STRONG&gt;instead of my DNS-Proxy Interface 192.168.29.245.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I have attached both pcaps from server and the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC5.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48047i88EE980CFA24CCB4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC5.jpg" alt="LC5.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC6.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48048i845564483588B969/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC6.jpg" alt="LC6.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2023 17:51:19 GMT</pubDate>
    <dc:creator>akilan.r@tutelartechlabs.com.panwpartner</dc:creator>
    <dc:date>2023-02-16T17:51:19Z</dc:date>
    <item>
      <title>Why Management interface do query instead of DNS-Proxy Interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-management-interface-do-query-instead-of-dns-proxy-interface/m-p/531454#M913</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I configured DNS proxy Interface e1/1 - 192.168.29.245 to clientless vpn.&lt;/P&gt;
&lt;P&gt;DNS-Proxy resolves as,&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;General browsing resolves with DNS 8.8.8.8 and 1.1.1.1&lt;/LI&gt;
&lt;LI&gt;Tutelartechlabs.com resolves with DNS 1.1.1.2 and 4.4.4.4&lt;/LI&gt;
&lt;LI&gt;Amazon.forest.in (internal-application) resolves with DNS 172.30.30.31&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48043iE7EB78D86C1B0679/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC1.jpg" alt="LC1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC2.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48044iB234722EADAD2D88/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC2.jpg" alt="LC2.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC3.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48045iCD023940258CCF48/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC3.jpg" alt="LC3.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC4.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48046iABF7CA957EB490F5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC4.jpg" alt="LC4.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;DNS-Proxy interface is the interface that act as a proxy and queries for dataplane traffic instead of management interface setup--&amp;gt;service--&amp;gt;DNS.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;so the question is why my &lt;STRONG&gt;management interface 192.168.29.250&amp;nbsp;&lt;/STRONG&gt;queries for a&lt;STRONG&gt;mazon.forest.in&lt;/STRONG&gt; to the DNS server when the application is accessed by a user in clientless-vpn&amp;nbsp; &lt;STRONG&gt;instead of my DNS-Proxy Interface 192.168.29.245.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I have attached both pcaps from server and the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC5.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48047i88EE980CFA24CCB4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC5.jpg" alt="LC5.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LC6.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48048i845564483588B969/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LC6.jpg" alt="LC6.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 17:51:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-management-interface-do-query-instead-of-dns-proxy-interface/m-p/531454#M913</guid>
      <dc:creator>akilan.r@tutelartechlabs.com.panwpartner</dc:creator>
      <dc:date>2023-02-16T17:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why Management interface do query instead of DNS-Proxy Interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-management-interface-do-query-instead-of-dns-proxy-interface/m-p/531723#M926</link>
      <description>&lt;P&gt;If you have correctly also attached the DNS proxy under the "Proxy" tab in the Clientless VPN then it could be a bug because you have the managment ip address in the same subnet as the data interface and I think that there was such an issue but I can't say for 100%.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Test if also configuring the service route for DNS to use the data plane interface will help or if possible to place the data plane interface in seperate subnet than the managment interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/service-routes" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/service-routes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 09:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/why-management-interface-do-query-instead-of-dns-proxy-interface/m-p/531723#M926</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-02-20T09:22:56Z</dc:date>
    </item>
  </channel>
</rss>

