<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Signature Lookup Timeout Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539782#M110732</link>
    <description>&lt;P&gt;not related to&amp;nbsp;&lt;SPAN&gt;app-id (default-app)&amp;nbsp;, still experience the issues&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 22 Apr 2023 08:44:35 GMT</pubDate>
    <dc:creator>nevolex</dc:creator>
    <dc:date>2023-04-22T08:44:35Z</dc:date>
    <item>
      <title>DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/344488#M86182</link>
      <description>&lt;P&gt;I'm seeing quite a lot of messages logged in the syslog output from my PA VM-100 running PAN-OS 10.0.0:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Aug 19 07:31:29 firewall-1 1,2020/08/19 07:31:29,007051000047085,SYSTEM,general,2560,2020/08/19 07:31:29,,general,,0,0,general,medium,"DNS signature lookup timed out",1461969,0x0,0,0,0,0,,firewall-1,0,0,1970-01-01T10:00:00.000+10:00&lt;/PRE&gt;&lt;P&gt;What exactly does "DNS signature lookup timed out" mean?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;My VM has two local DNS servers configured, which are functioning well and the PA VM has access to do direct external lookups as well if it needs to do so.&amp;nbsp; It is located on the end of a quiet 250/100M internet fibre connection here in Australia, so connectivity and congestion is not an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;EM&gt;DNS Signature Lookup Timeout (ms) &lt;/EM&gt;value is set to&amp;nbsp;300 - far far above what should be necessary.&lt;/P&gt;&lt;P&gt;Can anyone explain the traffic flow that might cause this (do these DNS queries go direct, or via configured resolver, and over what transport) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is an error, how do I go about debugging it to find the root cause?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Reuben&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 00:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/344488#M86182</guid>
      <dc:creator>ReubenFarrelly</dc:creator>
      <dc:date>2020-08-19T00:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/344512#M86186</link>
      <description>&lt;P&gt;Hi Mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest identifying which traffic is causing these errors. Is it legit DNS query being timed out. Worth playing with the timers once more try increasing more, maybe some queries are timing out genuinely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it is like hitting a wall again, would suggest getting in touch with Palo TAC. Could be cosmetic bug or genuine misconfiguraton.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;VR&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 02:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/344512#M86186</guid>
      <dc:creator>VarunRao</dc:creator>
      <dc:date>2020-08-19T02:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/352444#M87190</link>
      <description>&lt;P&gt;Thanks VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you suggest how I would find out what traffic it is?&amp;nbsp; The log message doesn't indicate much other than a DNS query timed out.&amp;nbsp; I'm assuming it is to do with the DNS Security feature.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can you or anyone else explain the traffic flow behind this feature?&amp;nbsp; I can't find it documented anywhere.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 06:37:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/352444#M87190</guid>
      <dc:creator>ReubenFarrelly</dc:creator>
      <dc:date>2020-09-28T06:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/408186#M92314</link>
      <description>&lt;P&gt;Any resolution to this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 18:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/408186#M92314</guid>
      <dc:creator>acanevari</dc:creator>
      <dc:date>2021-05-20T18:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/449775#M100974</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;I am also getting the same error in Paloalto. I changed the DNS signature lookup timeout to 2000 mseconds but still facing the same issue. Let me know if anyone got a solution or actual root cause of the issue&lt;/P&gt;</description>
      <pubDate>Sun, 28 Nov 2021 11:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/449775#M100974</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2021-11-28T11:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538223#M110525</link>
      <description>&lt;P&gt;I am&amp;nbsp; still facing the same issue, i have set the timers to 50000 &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 10:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538223#M110525</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-11T10:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538432#M110544</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280122"&gt;@nevolex&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In DNS security, there is a DP timeout for waiting for the DNS security verdict.&amp;nbsp; When a DNS response comes after the timeout and the FW does not have a verdict, this response lets through. If the verdict is received later and indicates the previously let-through domain was malicious, this log is generated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could disable DNS security or set actions to allow.&amp;nbsp; A permanent fix should be available in PAN-OS 10.0.10.&lt;/P&gt;
&lt;P&gt;If you're already running a newer PAN-OS version then you might be hitting a different issue and I would recommend reaching out to support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 11:29:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538432#M110544</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-04-12T11:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538582#M110559</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using version 10.2.4, how do I &lt;SPAN&gt;set actions to allow please?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I currently whitelisted io.dns.service.paloaltonetworks.com, not to use app-id policy&amp;nbsp;for that (I use service routes for palo alto inband traffic) and some of my policies have app-id with no ssl decryption&amp;nbsp; I noticed a few web services stopped working with app-ids, just too hard to fix when you just want to allow all from trust - to untrust zone &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Than you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 09:51:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538582#M110559</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-13T09:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538584#M110560</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280122"&gt;@nevolex&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can change the DNS Security actions in the Anti-Spyware profile:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1681380120565.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49433iC12C77715A1F82D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1681380120565.png" alt="kiwi_0-1681380120565.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/dns-security/enable-dns-security" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/dns-security/enable-dns-security&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might want to reach out to support to see if you're hitting the same issue as seen in PAN-OS 10.0 or if you're hitting a different issue entirely.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 10:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/538584#M110560</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-04-13T10:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539172#M110640</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eeoe.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49611i4F98000FF6CB3304/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="eeoe.png" alt="eeoe.png" /&gt;&lt;/span&gt;still having the same issue, very frustrating as Internet drops when that happens&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 03:21:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539172#M110640</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-19T03:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539656#M110704</link>
      <description>&lt;P&gt;the issue was very likely related to app-id (default-app) used in the outbound polices, allowing all the ports/ apps for paloato urls resolved the issue (works for 24 hours already without flapping )&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 06:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539656#M110704</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-21T06:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539782#M110732</link>
      <description>&lt;P&gt;not related to&amp;nbsp;&lt;SPAN&gt;app-id (default-app)&amp;nbsp;, still experience the issues&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 08:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/539782#M110732</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-04-22T08:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Signature Lookup Timeout Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/541299#M110962</link>
      <description>&lt;P&gt;it seems like the issue has been finally resolved by changing the mtu size on the wan interface to 1350bytes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 21:19:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-signature-lookup-timeout-error/m-p/541299#M110962</guid>
      <dc:creator>nevolex</dc:creator>
      <dc:date>2023-05-05T21:19:11Z</dc:date>
    </item>
  </channel>
</rss>

