<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Umbrella/OpenDNS queries now being flagged  as threat 18003 in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235045#M431</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you are still getting the alerts, I would update your dynamic definitions and maybe even open a TAC case to see what is/was causing the issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 11 Oct 2018 21:24:35 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-10-11T21:24:35Z</dc:date>
    <item>
      <title>Cisco Umbrella/OpenDNS queries now being flagged  as threat 18003</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/234940#M428</link>
      <description>&lt;P&gt;We use Cisco Umbreall/OpenDNS for secure DNS and web protection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Umbrella setup guide says that they use DNSCrypt for secure DNS queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This setup has worked flawless for years until about two weeks ago,. We began getting alerts that the two IP address from OpenDNS (Cisco Umbrella) are now being flagged periodically as threat 18003 DNS C2 Traffic.&amp;nbsp; Any reason why now the PA's are flagging and dropping this traffic?&amp;nbsp; It used to not do this. No changes to the OpenDNS/Cisco Umbrealla environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have verified with pcap traffic and other means that this is indeed traffic from OpenDNS connectors and Cisco Umbrella.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions would be helpful with helping silence these alerts. We obviously don't want to kill all alerts on C2 DNS traffic, just address the noisy false-positives that we are now seeing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 15:02:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/234940#M428</guid>
      <dc:creator>MarkBrophy</dc:creator>
      <dc:date>2018-10-11T15:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Umbrella/OpenDNS queries now being flagged  as threat 18003</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/234990#M429</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have not seen this behavior on my systems. The way we are setup is that clients contact internal DNS and only our DNS servers can get to OpenDNS for resolution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure your dynamic definitions are up to date. If that doesnt work, I would recommend opening a TAC case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 19:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/234990#M429</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-11T19:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Umbrella/OpenDNS queries now being flagged  as threat 18003</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235009#M430</link>
      <description>&lt;P&gt;That is how we are setup as well. The OpenDNS connectors are just the secure connections for the needed lookups by DNS servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 19:42:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235009#M430</guid>
      <dc:creator>MarkBrophy</dc:creator>
      <dc:date>2018-10-11T19:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Umbrella/OpenDNS queries now being flagged  as threat 18003</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235045#M431</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you are still getting the alerts, I would update your dynamic definitions and maybe even open a TAC case to see what is/was causing the issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 21:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235045#M431</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-11T21:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Umbrella/OpenDNS queries now being flagged  as threat 18003</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235157#M432</link>
      <description>&lt;P&gt;Mark, did you open a case with Support? We'd like to receive a DNSCrypt PCAP triggering the signature to provide it to our developers&amp;nbsp;to have the signature improved.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 17:41:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cisco-umbrella-opendns-queries-now-being-flagged-as-threat-18003/m-p/235157#M432</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-10-12T17:41:48Z</dc:date>
    </item>
  </channel>
</rss>

