<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can the internal DNS server be  behind SPN not a CAN? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/m-p/418538#M207</link>
    <description>&lt;P&gt;I think that also Authentication servers like LDAP and other services can be behind an security processing node if the Data Center does not have a good firewall (this is why service node seems a bad idea). As the Prisma Access is full mesh iBGP I will consider this the case as every source may connect to every destination (only for mobile gateways a&amp;nbsp; CAN even if it is without active ipsec tunnels is needed for routing) till someone says that this is not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto confirmed that this is the case.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 10:08:28 GMT</pubDate>
    <dc:creator>NikolayDimitrov</dc:creator>
    <dc:date>2021-08-05T10:08:28Z</dc:date>
    <item>
      <title>Can the internal DNS server be  behind SPN not a CAN?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/m-p/417558#M206</link>
      <description>&lt;P&gt;Can the internal global or specific&amp;nbsp;&amp;nbsp; internal DNS servers for mobile users or remote networks be behind SPN and not a CAN as the CAN is just there for routing for mobile users without a real active ipsec tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically I mean the internal DNS servers to be in the remote network address space that is connected to the SPN, because the SPN provides policy check and&amp;nbsp;ssl decryption as the Data Center firewalls is old layer3/4 with no ssl decryption, better use SPN than a CAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-users/quick-configs-for-user-deployments/dns-resolution-for-mobile-users-and-remote-networks" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-users/quick-configs-for-user-deployments/dns-resolution-for-mobile-users-and-remote-networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 06:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/m-p/417558#M206</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-07-08T06:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can the internal DNS server be  behind SPN not a CAN?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/m-p/418538#M207</link>
      <description>&lt;P&gt;I think that also Authentication servers like LDAP and other services can be behind an security processing node if the Data Center does not have a good firewall (this is why service node seems a bad idea). As the Prisma Access is full mesh iBGP I will consider this the case as every source may connect to every destination (only for mobile gateways a&amp;nbsp; CAN even if it is without active ipsec tunnels is needed for routing) till someone says that this is not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto confirmed that this is the case.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 10:08:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/m-p/418538#M207</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-08-05T10:08:28Z</dc:date>
    </item>
  </channel>
</rss>

