<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic Log query for FQDN object errors with &amp;quot;ip range [fqdn] expansion exceeds maximum number of items allowed&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/640326#M122127</link>
    <description>&lt;P&gt;I created a new FQDN object and added it to a security policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After committing changes, I tried to validate the rule was working, but I get this error in the traffic log when searching for &lt;STRONG&gt;(addr in 'my-FQDN-object')&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewHale_0-1732120150610.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64156i9E0907EEDFFA2007/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MatthewHale_0-1732120150610.png" alt="MatthewHale_0-1732120150610.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The security policy rule is not working either. It should allow access to this FQDN address, but is not triggering&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the correct address in the palo FQDN cache (using &lt;STRONG&gt;show dns-proxy fqdn all&lt;/STRONG&gt;). There's one IPv4 and one IPv6 result&lt;/P&gt;
&lt;P&gt;I also verified the Palo was able to resolve the FQDN while creating the object&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea what I'm missing here?&lt;/P&gt;
&lt;P&gt;Model: PA-850&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2024 16:44:29 GMT</pubDate>
    <dc:creator>Matthew-Hale</dc:creator>
    <dc:date>2024-11-20T16:44:29Z</dc:date>
    <item>
      <title>Traffic Log query for FQDN object errors with "ip range [fqdn] expansion exceeds maximum number of items allowed"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/640326#M122127</link>
      <description>&lt;P&gt;I created a new FQDN object and added it to a security policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After committing changes, I tried to validate the rule was working, but I get this error in the traffic log when searching for &lt;STRONG&gt;(addr in 'my-FQDN-object')&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MatthewHale_0-1732120150610.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64156i9E0907EEDFFA2007/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MatthewHale_0-1732120150610.png" alt="MatthewHale_0-1732120150610.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The security policy rule is not working either. It should allow access to this FQDN address, but is not triggering&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the correct address in the palo FQDN cache (using &lt;STRONG&gt;show dns-proxy fqdn all&lt;/STRONG&gt;). There's one IPv4 and one IPv6 result&lt;/P&gt;
&lt;P&gt;I also verified the Palo was able to resolve the FQDN while creating the object&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea what I'm missing here?&lt;/P&gt;
&lt;P&gt;Model: PA-850&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 16:44:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/640326#M122127</guid>
      <dc:creator>Matthew-Hale</dc:creator>
      <dc:date>2024-11-20T16:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Log query for FQDN object errors with "ip range [fqdn] expansion exceeds maximum number of items allowed"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/644802#M122150</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/210391"&gt;@Matthew-Hale&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You're setting up an FQDN on an IP range object. I recommend choosing the FQDN object instead and trying again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 20:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/644802#M122150</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-11-21T20:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Log query for FQDN object errors with "ip range [fqdn] expansion exceeds maximum number of items allowed"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/645071#M122153</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/326520"&gt;@jpomachagua&lt;/a&gt;&amp;nbsp;These are FQDN objects, despite the error message text. From the running config:&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;address {
  my-FQDN-object {
    fqdn sftp.host-id.domain.com;
  }
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Although I guess I'm not able to use those objects for searching traffic logs like I expected...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I made some other FQDN objects to test with, and those just say "invalid value" in the traffic monitor, which makes more sense. I'll have to investigate further why they're not matching in the rule&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 22:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-log-query-for-fqdn-object-errors-with-quot-ip-range-fqdn/m-p/645071#M122153</guid>
      <dc:creator>Matthew-Hale</dc:creator>
      <dc:date>2024-11-21T22:41:25Z</dc:date>
    </item>
  </channel>
</rss>

