<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS proxy not responding to requests in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/552702#M112430</link>
    <description>&lt;P&gt;I don't think you read all the details. Using&amp;nbsp;&lt;SPAN&gt;'test dns-proxy query' on the CLI also failed, proving any client DNS misconfig is not the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I went back to this and did some digging into dnsproxyd on a different deployment and found after the DNSproxy receives the DNS request on configured listening interfaces, it will send out DNS request to the correct IP according to its rules, however sends it on the interface it received the original DNS request on. It will ignore the DNS service interface/destination routes, as well as route tables. Unless there is a hidden setting not mentioned in the admin guides, looks like a bug to me.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This issue may not be encountered in larger deployments with multiple vsys, with the use of DNS profiles:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/dns/dns-server-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/dns/dns-server-profile&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 06 Aug 2023 22:02:35 GMT</pubDate>
    <dc:creator>BumblingFixer</dc:creator>
    <dc:date>2023-08-06T22:02:35Z</dc:date>
    <item>
      <title>DNS proxy not responding to requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/545694#M111579</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot seem to get DNS proxy working on a PAN-440 box for a simple network topology. Hosts on .20.0/24 subnet cannot resolve DNS using the proxy either from external or domain. I logged denied DNS requests to external DNS from ethernet 1/8's ip so created a rule to allow. Opening up the security policy a bit, the .20.0 hosts can resolve from external DNS directly, showing static routes are ok etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Used 'test dns-proxy query' and 'show dns-proxy cache all' with ethernet 1/8 and no entries logged (mgmt-obj using service routes had no problem). Weirdly enough, I got cached DNS entries ok when querying dns proxy using the external interface 1/1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anything I have overlooked? Thanks for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 04:37:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/545694#M111579</guid>
      <dc:creator>BumblingFixer</dc:creator>
      <dc:date>2023-06-13T04:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy not responding to requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/545770#M111589</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297299"&gt;@BumblingFixer&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you have your internal clients setup to utilize the dns-proxy properly you shouldn't need to allow your clients access to internal DNS servers, which&amp;nbsp;&lt;EM&gt;appears&amp;nbsp;&lt;/EM&gt;to be what you're doing from a brief glance at your configuration. The firewall will handle forwarding when required, the clients don't need access to those external providers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems like your clients aren't actually configured to utilize the dns-proxy configured interface IPs based off of what you're reporting. I'd double check that your clients are actually sending DNS requests to the interfaces you have dns-proxy enabled on, and that DNS isn't setup to still resolve to the external providers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:00:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/545770#M111589</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-06-13T14:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy not responding to requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/552702#M112430</link>
      <description>&lt;P&gt;I don't think you read all the details. Using&amp;nbsp;&lt;SPAN&gt;'test dns-proxy query' on the CLI also failed, proving any client DNS misconfig is not the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I went back to this and did some digging into dnsproxyd on a different deployment and found after the DNSproxy receives the DNS request on configured listening interfaces, it will send out DNS request to the correct IP according to its rules, however sends it on the interface it received the original DNS request on. It will ignore the DNS service interface/destination routes, as well as route tables. Unless there is a hidden setting not mentioned in the admin guides, looks like a bug to me.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This issue may not be encountered in larger deployments with multiple vsys, with the use of DNS profiles:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/dns/dns-server-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/dns/dns-server-profile&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2023 22:02:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-responding-to-requests/m-p/552702#M112430</guid>
      <dc:creator>BumblingFixer</dc:creator>
      <dc:date>2023-08-06T22:02:35Z</dc:date>
    </item>
  </channel>
</rss>

