<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there entry limit when resolving FQDN? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512930#M106553</link>
    <description>&lt;P&gt;When I tried resolve the FQDN, abc.com, and it shows 4 IP address of&lt;/P&gt;
&lt;P&gt;54.192.150.W,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;54.192.150.X,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;54.192.150.Y,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;54.192.150.Z&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use this address&lt;/P&gt;
&lt;P&gt;ipv6 not resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After I performed 'request system fqdn refresh force yes’&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The resolve FQDN shows another 4 IP address of&amp;nbsp;&lt;/P&gt;
&lt;P&gt;13.33.33.W&lt;/P&gt;
&lt;P&gt;13.33.33.X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use this address&lt;/P&gt;
&lt;P&gt;13.33.33.Y&lt;/P&gt;
&lt;P&gt;13.33.33.Z&lt;/P&gt;
&lt;P&gt;ipv6 not resolved&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both range of IP addresses are correct. But why does the firewall not show all the IP associated with the FQDN?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any display limit so that it can only display 4 IP addresses?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2022 04:13:10 GMT</pubDate>
    <dc:creator>Wenwei_Y</dc:creator>
    <dc:date>2022-08-25T04:13:10Z</dc:date>
    <item>
      <title>Is there entry limit when resolving FQDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512930#M106553</link>
      <description>&lt;P&gt;When I tried resolve the FQDN, abc.com, and it shows 4 IP address of&lt;/P&gt;
&lt;P&gt;54.192.150.W,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;54.192.150.X,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;54.192.150.Y,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;54.192.150.Z&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use this address&lt;/P&gt;
&lt;P&gt;ipv6 not resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After I performed 'request system fqdn refresh force yes’&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The resolve FQDN shows another 4 IP address of&amp;nbsp;&lt;/P&gt;
&lt;P&gt;13.33.33.W&lt;/P&gt;
&lt;P&gt;13.33.33.X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; use this address&lt;/P&gt;
&lt;P&gt;13.33.33.Y&lt;/P&gt;
&lt;P&gt;13.33.33.Z&lt;/P&gt;
&lt;P&gt;ipv6 not resolved&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both range of IP addresses are correct. But why does the firewall not show all the IP associated with the FQDN?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any display limit so that it can only display 4 IP addresses?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 04:13:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512930#M106553</guid>
      <dc:creator>Wenwei_Y</dc:creator>
      <dc:date>2022-08-25T04:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is there entry limit when resolving FQDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512942#M106557</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223419"&gt;@Wenwei_Y&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;while I can't think of explanation of what you are experiencing, it should not be display limit. The limit is 32 IP addresses:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to check a few FQDN objects we have configured and it is returning 8 or more IP addresses.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 05:20:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512942#M106557</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-08-25T05:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is there entry limit when resolving FQDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512945#M106558</link>
      <description>&lt;P&gt;This might be due to how the DNS server itself provides the information. There are services which have dozen on IPs assigned to it.&lt;/P&gt;
&lt;P&gt;If one does a name resolution (nslookup on Windows, host on Linux) of mail.office365.com, the result will be different every 10 seconds or so. This permits the provider to distribute to load among the different servers.&lt;/P&gt;
&lt;P&gt;If the destination will be called using web protocols, using an URL instead of fqdn might solve the issue. If the application is something different, then you have to fetch all possible IPs and add them to the policy (or an object-group).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 06:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/512945#M106558</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2022-08-25T06:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Is there entry limit when resolving FQDN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/513011#M106574</link>
      <description>&lt;P&gt;This is because of the DNS server response. abc.com authoritative DNS servers are only providing 4 A record responses at a time, from a larger record set, with 60 second TTL (a "slow" version of fast-flux DNS). The authoritative response also varies depending on where in the country the query is performed (region specific responses).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if you are using multiple distinct DNS servers, and those DNS servers get authoritative results from different authoritative servers. The local DNS server are frequently going to have different results and you will get whichever version of results responds the fastest. The PA is just working with the final result it got at the moment.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 16:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-entry-limit-when-resolving-fqdn/m-p/513011#M106574</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-08-25T16:18:21Z</dc:date>
    </item>
  </channel>
</rss>

