<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewalls is not resolving domain names in address groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524460#M108510</link>
    <description>&lt;P&gt;Have you also tried/checked if the DNS server (also configured on firewall) is able to resolve the external domains?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 19 Dec 2022 10:33:12 GMT</pubDate>
    <dc:creator>Arnesh</dc:creator>
    <dc:date>2022-12-19T10:33:12Z</dc:date>
    <item>
      <title>Firewalls is not resolving domain names in address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524455#M108507</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For some odd reason the firewall is not resolving external fqdn's that are part of an Address groups..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 09:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524455#M108507</guid>
      <dc:creator>LimaSupport</dc:creator>
      <dc:date>2022-12-19T09:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firewalls is not resolving domain names in address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524459#M108509</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154359"&gt;@LimaSupport&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you describe how do you confirm the firewall is unable to resolve the domains? Have you checked it from the GUI or CLI of firewall?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mostly, the reason for the firewall not able to resolve the FQDNs is due to the firewall unable to reach the DNS server.&lt;/P&gt;
&lt;P&gt;By default, mgmt interface is used to connect to the DNS server (but can be changed from &lt;I&gt;Device &amp;gt; Setup &amp;gt; Services &amp;gt; Service Route Configuration&lt;/I&gt;)&lt;/P&gt;
&lt;P&gt;You can check if the DNS server is reachable. T&lt;SPAN&gt;he CLI command below can then be used to view the list of FQDN objects and the IP addresses associated with that name.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PAN-OS 8.1 and below:&lt;STRONG&gt;&amp;nbsp;&amp;gt; request system fqdn show&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;PAN-OS 9.1 and above:&lt;STRONG&gt;&amp;nbsp;&amp;gt; show dns-proxy fqdn all&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Alternatively, you can also check the FQDN resolution on the GUI by navigating to Address Objects &amp;gt; Select the FQDN Address Object in question &amp;gt; Click on 'resolve'.&lt;/P&gt;
&lt;P&gt;Please go through the below KBs, which can be of help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_self"&gt;How to Configure and Test FQDN Objects&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POKrCAO" target="_self"&gt;DNSPROXY and FQDN address refresh behaviours - PANOS 9.0 and Above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 10:31:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524459#M108509</guid>
      <dc:creator>Arnesh</dc:creator>
      <dc:date>2022-12-19T10:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Firewalls is not resolving domain names in address groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524460#M108510</link>
      <description>&lt;P&gt;Have you also tried/checked if the DNS server (also configured on firewall) is able to resolve the external domains?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 10:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewalls-is-not-resolving-domain-names-in-address-groups/m-p/524460#M108510</guid>
      <dc:creator>Arnesh</dc:creator>
      <dc:date>2022-12-19T10:33:12Z</dc:date>
    </item>
  </channel>
</rss>

