<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS not DNS? Strange UDP 53? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13806#M10127</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing a huge amount of traffic outbound from my DNS server that seems to be being dropped by the firewall. Its being dropped because my application rule says "allow DNS server to talk DNS to the internet", it doesn't match that (because its not DNS application according to PAN) and so its dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats happening is that there is a large amount of UDP 53 traffic that's not being classified as DNS application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone seen this before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thoughts from me are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Its some sort of DNS tunnelling going on (possible I suppose? Could be a variation PAN don't know about)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The DNS traffic is doing authoritative lookups on non-Latin domain names and the unicoding of the request is not supported by PAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Being UDP obviously it could be a spoofed source I suppose (seems unlikely so far)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have yet to fully investigate it (packet captures etc) but just wondered if anyone has seen this and/or if my idea #2 is a possibility?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Nov 2014 21:57:56 GMT</pubDate>
    <dc:creator>Andy_K</dc:creator>
    <dc:date>2014-11-04T21:57:56Z</dc:date>
    <item>
      <title>DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13806#M10127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing a huge amount of traffic outbound from my DNS server that seems to be being dropped by the firewall. Its being dropped because my application rule says "allow DNS server to talk DNS to the internet", it doesn't match that (because its not DNS application according to PAN) and so its dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats happening is that there is a large amount of UDP 53 traffic that's not being classified as DNS application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone seen this before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thoughts from me are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Its some sort of DNS tunnelling going on (possible I suppose? Could be a variation PAN don't know about)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The DNS traffic is doing authoritative lookups on non-Latin domain names and the unicoding of the request is not supported by PAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Being UDP obviously it could be a spoofed source I suppose (seems unlikely so far)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have yet to fully investigate it (packet captures etc) but just wondered if anyone has seen this and/or if my idea #2 is a possibility?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 21:57:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13806#M10127</guid>
      <dc:creator>Andy_K</dc:creator>
      <dc:date>2014-11-04T21:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13807#M10128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you look at the Bytes Sent and see the size of the traffic. What is the application it is classified as? Next if you do a test url for url in question, see what category you are getting. Also under Spyware setting, what is DNS action set to? Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 22:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13807#M10128</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-04T22:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13808#M10129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its classified as "N/A" and the sizes are a range (I've got about 55,000 lines of log messages I'm looking at with it in...) is between 67 bytes and 140 bytes - a big mixture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand what you mean about a test url?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no spyware detection for this traffic, its just dropped traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 22:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13808#M10129</guid>
      <dc:creator>Andy_K</dc:creator>
      <dc:date>2014-11-04T22:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13809#M10130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you check PAN threat logs, if any suspicious activity has been captured for this type of traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 22:09:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13809#M10130</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-04T22:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13810#M10131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, nothing in the threat log, its just being dropped by the firewall rules because its not DNS application according to PAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 22:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13810#M10131</guid>
      <dc:creator>Andy_K</dc:creator>
      <dc:date>2014-11-04T22:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13811#M10132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In that case we need to get pcap from traffic in question if that is possible and analyze what type of packets are those. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 23:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13811#M10132</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-11-04T23:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS not DNS? Strange UDP 53?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13812#M10133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm going to give that a go hopefully tomorrow, was just wondering in the meantime if anyone else had ever seen this type of traffic before?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Nov 2014 23:15:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-not-dns-strange-udp-53/m-p/13812#M10133</guid>
      <dc:creator>Andy_K</dc:creator>
      <dc:date>2014-11-04T23:15:02Z</dc:date>
    </item>
  </channel>
</rss>

