<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: issues using aka.ms in a firewall rule in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509546#M106073</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37508"&gt;@JimMcGrady&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The issue that you'll run into, even if setup as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;mentioned, is that CDNs like Akami don't have the TTL set to expire as often as they rotate clients to different hosts. This is&amp;nbsp;&lt;EM&gt;slightly&amp;nbsp;&lt;/EM&gt;better if you have the firewall and all connected clients using the same DNS servers, but you can still have the firewall and the client get out of sync even then.&lt;/P&gt;
&lt;P&gt;With Microsoft in particular I&amp;nbsp;&lt;EM&gt;highly&amp;nbsp;&lt;/EM&gt;recommend using URL Filtering to limit this traffic instead of trying to utilize FQDN objects if you can. There's imperfect lists of associated Windows update IPs that you can tie with URL Filtering in more secure environments, but FQDNs never work properly for this.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jul 2022 22:13:15 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-07-21T22:13:15Z</dc:date>
    <item>
      <title>issues using aka.ms in a firewall rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509359#M106034</link>
      <description>&lt;P&gt;Microsoft makes extensive use of the name aka.ms to map to thousands of IPs in its Akamai content delivery network.&lt;/P&gt;
&lt;P&gt;I find that i have issues trying to use FQDN host object aka.ms in a firewall rule. Many times traffic doesnt hit the rule.&lt;/P&gt;
&lt;P&gt;I suspect its because Palo's periodic update of its IP table for aka.ms misses some of the addresses in use.&lt;/P&gt;
&lt;P&gt;Has anyone else experienced this?&amp;nbsp; I'm running PA 9.1.13&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 08:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509359#M106034</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2022-07-20T08:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: issues using aka.ms in a firewall rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509528#M106069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37508"&gt;@JimMcGrady&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you have set for your m&lt;SPAN&gt;inimum FQDN refresh time? You can try setting it to 0.&amp;nbsp;refresh The FQDN refresh will be based on the TTL set in DNS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 18:46:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509528#M106069</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-07-21T18:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: issues using aka.ms in a firewall rule</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509546#M106073</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37508"&gt;@JimMcGrady&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The issue that you'll run into, even if setup as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;mentioned, is that CDNs like Akami don't have the TTL set to expire as often as they rotate clients to different hosts. This is&amp;nbsp;&lt;EM&gt;slightly&amp;nbsp;&lt;/EM&gt;better if you have the firewall and all connected clients using the same DNS servers, but you can still have the firewall and the client get out of sync even then.&lt;/P&gt;
&lt;P&gt;With Microsoft in particular I&amp;nbsp;&lt;EM&gt;highly&amp;nbsp;&lt;/EM&gt;recommend using URL Filtering to limit this traffic instead of trying to utilize FQDN objects if you can. There's imperfect lists of associated Windows update IPs that you can tie with URL Filtering in more secure environments, but FQDNs never work properly for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 22:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-using-aka-ms-in-a-firewall-rule/m-p/509546#M106073</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-07-21T22:13:15Z</dc:date>
    </item>
  </channel>
</rss>

