<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS over TLS in 10.2.4 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538233#M110527</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280122"&gt;@nevolex&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was unable to find an existing feature request for it either.&lt;/P&gt;
&lt;P&gt;You could ask your local SE to file a feature request for it after which you and everyone else can add their vote to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 12:17:28 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2023-04-11T12:17:28Z</dc:date>
    <item>
      <title>DNS over TLS in 10.2.4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538064#M110501</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it seems like late last year DNS over TLS feature has been added to Palo Alto firewalls&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However I am having issues understanding where it needs to be configured, I did read the guides but still unclear&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my external dns is 1.1.1.1 and I use DNZ proxy, 1.1.1.1 does support dns over tls but for that a domain needs to be configured instead of the ip&lt;/P&gt;
&lt;P&gt;&lt;A href="https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-tls/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-tls/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the dns proxy does not allow fqdns to be configured only ips....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also have default dns security applied to a policy (per the guide it needs to "inspect traffic") but I don't know what that actually means (is that what packet capture is in there per dns category???)&lt;/P&gt;
&lt;P&gt;I also created a description policy for tcp 853 - no hits there&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the logs the firewall sends all the dns traffic over port 53, nothing goes over 853&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on a FortiGate it was very clear how this is set, but I am scratching my head how it's done on a palo alto&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please advise?&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 01:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538064#M110501</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-10T01:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNS over TLS in 10.2.4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538220#M110522</link>
      <description>&lt;P&gt;Ok, it looks like that Palo alto does not support that neither, that dns over tls support from the manual is for decryption purposes only in case if clients send traffic over tls, however what I mean is tls traffic dns forwarding, where the clients send the traffic via normal port 53, then the firewall sends that traffic over 853&amp;nbsp; to the external dns server like 1.1.1.1 for domain resolution&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks Palo alto DNS Proxy app does not support secure dns at all:(&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 07:44:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538220#M110522</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-12T07:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS over TLS in 10.2.4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538233#M110527</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280122"&gt;@nevolex&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was unable to find an existing feature request for it either.&lt;/P&gt;
&lt;P&gt;You could ask your local SE to file a feature request for it after which you and everyone else can add their vote to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 12:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-over-tls-in-10-2-4/m-p/538233#M110527</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-04-11T12:17:28Z</dc:date>
    </item>
  </channel>
</rss>

