<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External DNS resolution for specific domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/external-dns-resolution-for-specific-domains/m-p/488139#M104784</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to look for a solution to an issue we have whereas we don't want to add routes from Azure (via ExpressRoute) to an on premise for public IP's for which Azure devices need to connect to via a Palo Alto firewall and across a VPN to a 3rd party.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment we have configured an FQDN NAT on our Palo Alto firewalls (where the connection routes through) and currently our internal DNS is learning the name resolution externally so the connection kind of works for now but we need to add DNS zones and entries for where we are trying to connect to which will map the fqdn to the NAT address. Which will break connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have had a look at DNS proxy and I don't think that will work as we don't want to configure the Azure hosts with the firewall IP address for DNS as that will break other things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect we are going to have to bite the bullet and allow the routing across from Azure unless there is a means of making external DNS work for this specific traffic.&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 09:23:37 GMT</pubDate>
    <dc:creator>StuartS</dc:creator>
    <dc:date>2022-05-18T09:23:37Z</dc:date>
    <item>
      <title>External DNS resolution for specific domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dns-resolution-for-specific-domains/m-p/488139#M104784</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to look for a solution to an issue we have whereas we don't want to add routes from Azure (via ExpressRoute) to an on premise for public IP's for which Azure devices need to connect to via a Palo Alto firewall and across a VPN to a 3rd party.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment we have configured an FQDN NAT on our Palo Alto firewalls (where the connection routes through) and currently our internal DNS is learning the name resolution externally so the connection kind of works for now but we need to add DNS zones and entries for where we are trying to connect to which will map the fqdn to the NAT address. Which will break connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have had a look at DNS proxy and I don't think that will work as we don't want to configure the Azure hosts with the firewall IP address for DNS as that will break other things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect we are going to have to bite the bullet and allow the routing across from Azure unless there is a means of making external DNS work for this specific traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 09:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dns-resolution-for-specific-domains/m-p/488139#M104784</guid>
      <dc:creator>StuartS</dc:creator>
      <dc:date>2022-05-18T09:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: External DNS resolution for specific domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/external-dns-resolution-for-specific-domains/m-p/507800#M105769</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144955"&gt;@StuartS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you only add the entries you need to your internal DNS, why or which connections will be broken by this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you only need a few entries, then NAT seems to me like a good solution - if everything is passing your firewall, then I think you don't even need to mess with static DNS entries for this.&lt;/P&gt;
&lt;P&gt;... or I don't understand your issue correctly &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 16:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/external-dns-resolution-for-specific-domains/m-p/507800#M105769</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2022-07-03T16:53:28Z</dc:date>
    </item>
  </channel>
</rss>

