<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FQDN security in policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-security-in-policy/m-p/476570#M103592</link>
    <description>&lt;P&gt;Hi All, I am quite new to palo alto. can anyone explain me what happened if we configured object as a FQDN, IP and URL..I have created one security policy where I have implemented destination as a FQDN (nslookup results into 1 IP address) but user is reporting that it's not working..For that, FQDN default TTL is 5 mins, refresh time is 6 hours..&lt;BR /&gt;and How can we defined whether need to configured address as FQDN or URL, how TTL value play the role in that ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 09:00:13 GMT</pubDate>
    <dc:creator>PujaMandavgade</dc:creator>
    <dc:date>2022-03-29T09:00:13Z</dc:date>
    <item>
      <title>FQDN security in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-security-in-policy/m-p/476570#M103592</link>
      <description>&lt;P&gt;Hi All, I am quite new to palo alto. can anyone explain me what happened if we configured object as a FQDN, IP and URL..I have created one security policy where I have implemented destination as a FQDN (nslookup results into 1 IP address) but user is reporting that it's not working..For that, FQDN default TTL is 5 mins, refresh time is 6 hours..&lt;BR /&gt;and How can we defined whether need to configured address as FQDN or URL, how TTL value play the role in that ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 09:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-security-in-policy/m-p/476570#M103592</guid>
      <dc:creator>PujaMandavgade</dc:creator>
      <dc:date>2022-03-29T09:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN security in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-security-in-policy/m-p/476645#M103602</link>
      <description>&lt;P&gt;How have you implemented the firewall rules? And have you searched the traffic logs to see if the user is getting blocked/filtered through a different firewall rule than expected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FQDNs and IPs are essentially the same and match on the source or destination IP address in the Security Policy, with the exception that FQDN objects will automatically update if the IP address changes. However, it is important to remember that you client may not have the same root DNS source and therefore might not be going to the same IP for a given FQDN and the PaloAlto resolves. Also, some sites use fast-flux DNS, where the IP is constantly changing and only some IPs are returned at any given time from a large set of possible IPs, so it is basically impossible to keep the PA and client DNS responses consistent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A URL object matches in HTTP/HTTPS/etc. protocol traffic, but is never resolved to an IP. A security policy with a URL object is looking at the HTTP headers to extract the target URL (which may exist across multiple IPs or multiple unrelated URLs may reside on the same server IP). If you are using URL objects be sure to terminate them correctly as the wildcard matching may not always work as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A simple URL object Security Policy can also be tricky to implement because many websites may appear to be at a simple URL, but the page actually includes lots of resources from many other URLs and domains. You may also need to be running SSL decryption to get full use out of URL objects (to be able to see all the URLs in the session).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 16:41:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-security-in-policy/m-p/476645#M103602</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-29T16:41:18Z</dc:date>
    </item>
  </channel>
</rss>

