<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN Object in Policy - not working but FQDN seems to resolve properly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563959#M114166</link>
    <description>&lt;P&gt;The FQDN showed up correctly after executing the show dns-proxy fqdn all command.&amp;nbsp; I added an FQDN object for it again to the same rule and it showed up as 0.0.0.0 still.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, when I added another rule with that FQDN object it showed up with the IP and then thereafter even modifying the original rule it showed up with an IP when running "show running security-policy" so now I'm not sure what happened or why it works now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Previously, all I ever got was 0.0.0.0 in the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll leave it and see if this persists as usable for the time being.&amp;nbsp; It would be great if it does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for everyone's help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S I'm still on 10.0.6 on this FW - is it possible this is a bug?&amp;nbsp; I'll be updating to 10.2.5 soon.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Nov 2023 20:51:47 GMT</pubDate>
    <dc:creator>TonyDeHart</dc:creator>
    <dc:date>2023-11-01T20:51:47Z</dc:date>
    <item>
      <title>FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563707#M114136</link>
      <description>&lt;P&gt;I've never had the opportunity to use or need to use an FQDN in a security policy before but my first attempt to do so does not seem to be working. I'm trying to use an FQDN to restrict IPSEC/IKE traffic from a Virtual Network Gateway (VNG) in Azure.&amp;nbsp; The public IP has to be dynamically assigned and we tear down the VNG and put it back in place periodically and each time it is created it gets a NEW public IP address.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can point to the FQDN for this public IP address and it appears to resolve properly both in the GUI and from the CLI.&amp;nbsp; In fact, showing the VPN gateways shows it pointing to the proper public IP in azure using the FQDN.&amp;nbsp; However, the security policy keeps missing the traffic for some reason and it falls through to the clean up deny rule.&amp;nbsp; I don't understand why and I'm not certain how to troubleshoot this as the DNS lookups and other items seem to be using the proper IP for the FQDN defined.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI - the security policy is simply two objects - destination FQDN and outside IP of the firewall allowing IKE/IPSEC.&amp;nbsp; Statically defining the IP for the object in the rule works fine. Switching to an FQDN object is where it fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 13:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563707#M114136</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-10-31T13:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563929#M114157</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That seems odd. Could you share a screenshot of the traffic as well as the policy created? Can you try creating removing IKE/IPSEC in the app and set it to an allow any for testing purposes to see if traffic hits the policy?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 17:57:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563929#M114157</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-11-01T17:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563931#M114158</link>
      <description>&lt;P&gt;I can't this afternoon but can probably give it a shot sometime tomorrow when I can put the rules back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even if I can't use it I'd like to understand why it does or does not work and how it works.&amp;nbsp; Interestingly at the CLI when I show the security policy where the FQDN goes I see 0.0.0.0 in its place in the source/destination.&amp;nbsp; Is that normal?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 18:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563931#M114158</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-11-01T18:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563932#M114159</link>
      <description>&lt;P&gt;In Windows command prompt run&lt;/P&gt;
&lt;P&gt;nslookup -debug example.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change example.com to domain you are using as FQDN.&lt;/P&gt;
&lt;P&gt;Look up what TTL this domain has.&lt;/P&gt;
&lt;P&gt;I sometimes see as crazy as 5 second TTLs around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If domain has short TTL then Palo might time out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to Change the FQDN Refresh Timers&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKbCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKbCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FAST-DNS Resolution Issues&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boQJCAY" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boQJCAY&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 18:38:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563932#M114159</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-01T18:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563934#M114160</link>
      <description>&lt;P&gt;Admittedly it is very short at 1 minute but I don't control it as its assigned by Azure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;(default TTL = 60 (1 min))&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fqdn resolves properly in the CLI and more importantly, the IPSEC tunnel uses it when defined there. It is just the object itself fails in the security policy.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 18:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563934#M114160</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-11-01T18:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563935#M114161</link>
      <description>&lt;P&gt;Check what value is in FQDN cache.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PAN-OS 8.1 and below:&lt;STRONG&gt;&amp;nbsp;&amp;gt; request system fqdn show&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;PAN-OS 9.1 and above:&lt;STRONG&gt;&amp;nbsp;&amp;gt; show dns-proxy fqdn all&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 18:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563935#M114161</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-01T18:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563959#M114166</link>
      <description>&lt;P&gt;The FQDN showed up correctly after executing the show dns-proxy fqdn all command.&amp;nbsp; I added an FQDN object for it again to the same rule and it showed up as 0.0.0.0 still.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, when I added another rule with that FQDN object it showed up with the IP and then thereafter even modifying the original rule it showed up with an IP when running "show running security-policy" so now I'm not sure what happened or why it works now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Previously, all I ever got was 0.0.0.0 in the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll leave it and see if this persists as usable for the time being.&amp;nbsp; It would be great if it does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for everyone's help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S I'm still on 10.0.6 on this FW - is it possible this is a bug?&amp;nbsp; I'll be updating to 10.2.5 soon.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 20:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/563959#M114166</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-11-01T20:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN Object in Policy - not working but FQDN seems to resolve properly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/564080#M114171</link>
      <description>&lt;P&gt;So I ran an "experiment" of sorts this morning to see if this FQDN policy really sticks and works and found an interesting anomaly which I can only chalk up to bug or some sort of CLI issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I spun up the VGN in Azure which of course assigned a new IP address to my FQDN, the endpoint immediately showed up properly using the "show dns-proxy fqdn all".&amp;nbsp; However, using the "show running security-policy" command continues to show the OLD IP address in the policy information. Despite this, the IPSEC tunnel comes up and the GUI shows a match on the FQDN rule. The IPSEC Tunnel activation however took a short bit of time so it wasn't immediate but it doesn't appear the "show running security-policy" is a reliable indicator of what IP address is actually being used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Either way, I'm happy! It works and I can avoid changing the rules/objects every time we tear this down and turn it back up again.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 12:35:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-in-policy-not-working-but-fqdn-seems-to-resolve/m-p/564080#M114171</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-11-02T12:35:11Z</dc:date>
    </item>
  </channel>
</rss>

