<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN URLs that change IP addresses quickly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471468#M103100</link>
    <description>&lt;P&gt;I did have a VM of that installed but it lit up our vulnerability console like a Christmas tree.&amp;nbsp; When I updated Ubuntu to a newer release, that fixed the vulnerabilities but broke minemeld.&amp;nbsp; If its EoL I wonder if PA has any future plans for it, or better yet just build this right into PANOS, why require an external server to do all this legwork.&amp;nbsp; Maybe that's on the roadmap.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 18:56:08 GMT</pubDate>
    <dc:creator>ksauer507</dc:creator>
    <dc:date>2022-03-08T18:56:08Z</dc:date>
    <item>
      <title>FQDN URLs that change IP addresses quickly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471452#M103098</link>
      <description>&lt;P&gt;PA-3220 Active/Standby Pair&lt;/P&gt;&lt;P&gt;10.0.8-h8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a URL we tried adding to a negate policy for inside to outside decryption.&amp;nbsp; This resolves the ability to pull credit reports into our core financial system.&amp;nbsp; However the problem is still intermittent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its added as an FQDN object.&amp;nbsp; Here's the thing, If I do an nslookup or go to digwebinterface.com and look it up across multiple DNS servers, it always gives a different IP address.&amp;nbsp; Without knowing all of their IP's or knowing if they would ever change... we put it in as an FQDN object.&amp;nbsp; Do you think its only periodically pulling one IP but then the traffic is coming from one of their other IPs?&amp;nbsp; Its on an akami CDN and we don't want to whitelist all of akami.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 18:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471452#M103098</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-03-08T18:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN URLs that change IP addresses quickly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471465#M103099</link>
      <description>&lt;P&gt;Sounds like you could benefit from &lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld" target="_self"&gt;Minemeld&lt;/A&gt;. Dynamically generate an EDL. It went EoL 8/1/21, but it is community supported here on LiveCommunity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 18:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471465#M103099</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-03-08T18:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN URLs that change IP addresses quickly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471468#M103100</link>
      <description>&lt;P&gt;I did have a VM of that installed but it lit up our vulnerability console like a Christmas tree.&amp;nbsp; When I updated Ubuntu to a newer release, that fixed the vulnerabilities but broke minemeld.&amp;nbsp; If its EoL I wonder if PA has any future plans for it, or better yet just build this right into PANOS, why require an external server to do all this legwork.&amp;nbsp; Maybe that's on the roadmap.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 18:56:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471468#M103100</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-03-08T18:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN URLs that change IP addresses quickly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471484#M103105</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/178800"&gt;@ksauer507&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;...Its added as an FQDN object.&amp;nbsp; Here's the thing, If I do an nslookup or go to digwebinterface.com and look it up across multiple DNS servers, it always gives a different IP address.&amp;nbsp; Without knowing all of their IP's or knowing if they would ever change... we put it in as an FQDN object.&amp;nbsp; Do you think its only periodically pulling one IP but then the traffic is coming from one of their other IPs?&amp;nbsp; Its on an akami CDN and we don't want to whitelist all of akami.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What you are describing is Fast Flux DNS... and yes it is a pain to deal with. Basically, you can never insure the DNS result the firewall gets and the result the end client gets, will be the same. The PA will do a DNS lookup for the FQDN object and cache the results. With FFDNS this may be a half dozen results with a very short TTL, say 30 seconds (the PA will cache a maximum of 10 results I believe). But when the client does a nslookup a second or two later it gets 6 different results with a short TTL. 15 seconds after the PA first queried the FQDN in DNS, it refreshes again and gets yet another set of results, invalidating the first set. So the end result is that you can never be certain that the PA and end client are going to have the same DNS results at the same time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can get around this doing URL inspection for normal rules, but for doing decryption bypass this is a major pain... My only solution was to setup a script to probe DNS for all the results over time and add them all to an IP address object group included in the do-not-decrypt rule. But then a month or two later the Akami cluster would change and I would have to reprobe/update all the IPs. For us, a bunch of these cases were ultimately caused by Java apps with their own internal cert stores (doesn't use the system store) that we eventually forced our corporate CA cert into to be able to do decryption on the traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 20:31:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471484#M103105</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-08T20:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN URLs that change IP addresses quickly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471499#M103107</link>
      <description>&lt;P&gt;Ok all connections to this site are from one machine, so we did a negate rule on the source from this machine.&amp;nbsp; So far it seems our random connection issues have been resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its an ok risk for this one machine to not be in a decryption policy.&amp;nbsp; In fact its a lot of financial data, we know what it is and its probably better its not tampered with.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 21:45:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/471499#M103107</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-03-08T21:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN URLs that change IP addresses quickly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/475010#M103409</link>
      <description>&lt;P&gt;It isn't on the roadmap but the functionality has been ingested by &lt;A href="https://www.paloaltonetworks.com/cortex/threat-intel-management" target="_self"&gt;Cortex XSOAR Threat Intel Management (TIM)&lt;/A&gt;. &lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 17:08:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-urls-that-change-ip-addresses-quickly/m-p/475010#M103409</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2022-03-22T17:08:21Z</dc:date>
    </item>
  </channel>
</rss>

