<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to resolve internal url's after implementing dns security. in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/unable-to-resolve-internal-url-s-after-implementing-dns-security/m-p/349956#M940</link>
    <description>&lt;P&gt;No, you need to whitelist the domain in the DNS Security local cache.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you ran PAN-OS 10.0 you can configure domain exceptions in the Anti-Spyware profile, but for 9.0 and 9.1 the exception is global and you need to configure it from the CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I added instructions in this post&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/disney-domain-being-sinkholed-as-dns-tunneling-domain/m-p/325813" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/disney-domain-being-sinkholed-as-dns-tunneling-domain/m-p/325813&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be best to investigate why your internal domain is considered malicious though. It could be an FP and could be whitelisted in the cloud.&lt;/P&gt;
&lt;P&gt;You can try to see if the domain is listed as a malicious URL Category in&amp;nbsp;&lt;A href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/query/&lt;/A&gt;&amp;nbsp;and if it is, request a category change to an otherwise benign category. That will propagate a signal from PAN-DB to DNS Security to also whitelist the domain.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 21:52:40 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2020-09-16T21:52:40Z</dc:date>
    <item>
      <title>Unable to resolve internal url's after implementing dns security.</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/unable-to-resolve-internal-url-s-after-implementing-dns-security/m-p/346047#M930</link>
      <description>&lt;P&gt;I only would like to know if we add&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;*.domain.in&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in External dynamic list and if we call that EDL in Antispyware profile with action Alert, then EDL will take preference with alert action and exclude it or DNS security will take preference with sinkhole action.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Dns security.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27558iD8F5C2DCC5E71A2E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Dns security.PNG" alt="Dns security.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 10:15:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/unable-to-resolve-internal-url-s-after-implementing-dns-security/m-p/346047#M930</guid>
      <dc:creator>OsamaKhan</dc:creator>
      <dc:date>2020-08-31T10:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to resolve internal url's after implementing dns security.</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/unable-to-resolve-internal-url-s-after-implementing-dns-security/m-p/349956#M940</link>
      <description>&lt;P&gt;No, you need to whitelist the domain in the DNS Security local cache.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you ran PAN-OS 10.0 you can configure domain exceptions in the Anti-Spyware profile, but for 9.0 and 9.1 the exception is global and you need to configure it from the CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I added instructions in this post&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/disney-domain-being-sinkholed-as-dns-tunneling-domain/m-p/325813" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/disney-domain-being-sinkholed-as-dns-tunneling-domain/m-p/325813&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would be best to investigate why your internal domain is considered malicious though. It could be an FP and could be whitelisted in the cloud.&lt;/P&gt;
&lt;P&gt;You can try to see if the domain is listed as a malicious URL Category in&amp;nbsp;&lt;A href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/query/&lt;/A&gt;&amp;nbsp;and if it is, request a category change to an otherwise benign category. That will propagate a signal from PAN-DB to DNS Security to also whitelist the domain.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 21:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/unable-to-resolve-internal-url-s-after-implementing-dns-security/m-p/349956#M940</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-09-16T21:52:40Z</dc:date>
    </item>
  </channel>
</rss>

