<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying the DNSProxy feature for Static Response in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trying-the-dnsproxy-feature-for-static-response/m-p/1244577#M125755</link>
    <description>&lt;P&gt;Hie,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Situation - Wanted to kaminsky the DNS Responses for my client from the FW&lt;BR /&gt;Complication - None of the dig are responded&lt;/P&gt;
&lt;P&gt;Need your help on this?&lt;/P&gt;
&lt;P&gt;Client Requests for Promise/Spoofed IP&lt;/P&gt;
&lt;P&gt;keviv@keviv-VMware-Virtual-Platform:~$ ifconfig ens37&lt;BR /&gt;ens37: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt; mtu 1500&lt;BR /&gt;inet 192.168.21.21 netmask 255.255.255.0 broadcast 192.168.21.255&lt;BR /&gt;inet6 fe80::355a:6e06:90e9:6b84 prefixlen 64 scopeid 0x20&amp;lt;link&amp;gt;&lt;BR /&gt;ether 00:0c:29:80:6e:57 txqueuelen 1000 (Ethernet)&lt;BR /&gt;RX packets 7725 bytes 677203 (677.2 KB)&lt;BR /&gt;RX errors 0 dropped 0 overruns 0 frame 0&lt;BR /&gt;TX packets 7358 bytes 686142 (686.1 KB)&lt;BR /&gt;TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0&lt;/P&gt;
&lt;P&gt;keviv@keviv-VMware-Virtual-Platform:~$ dig @192.168.20.130 fallout.gcc&lt;BR /&gt;;; communications error to 192.168.20.130#53: timed out&lt;BR /&gt;;; communications error to 192.168.20.130#53: timed out&lt;BR /&gt;;; communications error to 192.168.20.130#53: timed out&lt;/P&gt;
&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.18.39-0ubuntu0.24.04.2-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; @192.168.20.130 fallout.gcc&lt;BR /&gt;; (1 server found)&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; no servers could be reached&lt;BR /&gt;keviv@keviv-VMware-Virtual-Platform:~$ dig @192.168.21.20 fallout.gcc&lt;BR /&gt;;; communications error to 192.168.21.20#53: timed out&lt;BR /&gt;;; communications error to 192.168.21.20#53: timed out&lt;BR /&gt;;; communications error to 192.168.21.20#53: timed out&lt;/P&gt;
&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.18.39-0ubuntu0.24.04.2-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; @192.168.21.20 fallout.gcc&lt;BR /&gt;; (1 server found)&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; no servers could be reached&lt;BR /&gt;keviv@keviv-VMware-Virtual-Platform:~$&lt;/P&gt;
&lt;P&gt;Firewall Config&lt;/P&gt;
&lt;P&gt;admin@panama# show network dns-proxy astroid&lt;BR /&gt;astroid {&lt;BR /&gt;cache {&lt;BR /&gt;max-ttl {&lt;BR /&gt;enabled no;&lt;BR /&gt;}&lt;BR /&gt;enabled yes;&lt;BR /&gt;}&lt;BR /&gt;tcp-queries {&lt;BR /&gt;enabled no;&lt;BR /&gt;}&lt;BR /&gt;static-entries {&lt;BR /&gt;cachepoisioning {&lt;BR /&gt;address 192.168.20.129;&lt;BR /&gt;domain fallout.gcc;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;interface [ ethernet1/1 ethernet1/2];&lt;BR /&gt;default {&lt;BR /&gt;primary 192.168.20.130;&lt;BR /&gt;}&lt;BR /&gt;enabled yes;&lt;BR /&gt;}&lt;BR /&gt;[edit]&lt;BR /&gt;admin@panama#&lt;/P&gt;
&lt;P&gt;admin@panama&amp;gt; show interface ethernet1/1&lt;BR /&gt;Interface IP address: 192.168.20.130/24&lt;/P&gt;
&lt;P&gt;admin@panama&amp;gt; show interface ethernet1/2&lt;BR /&gt;Interface IP address: 192.168.21.20/24&lt;/P&gt;
&lt;P&gt;admin@panama&amp;gt; show dns-proxy cache name astroid&lt;/P&gt;
&lt;P&gt;Name: astroid&lt;BR /&gt;Cache settings:&lt;BR /&gt;cache-edns: enabled&lt;BR /&gt;entries: 0&lt;BR /&gt;Domain IP/Name Type Class TTL Hits&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="mailto:admin@panama&amp;gt;" target="_blank"&gt;admin@panama&amp;gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is currently all allow policy ord.&lt;BR /&gt;&lt;BR /&gt;Any suggestions or hint will be welcomed.&amp;nbsp;&lt;BR /&gt;Chao&lt;/P&gt;</description>
    <pubDate>Wed, 24 Dec 2025 19:59:42 GMT</pubDate>
    <dc:creator>ocpfn4</dc:creator>
    <dc:date>2025-12-24T19:59:42Z</dc:date>
    <item>
      <title>Trying the DNSProxy feature for Static Response</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-the-dnsproxy-feature-for-static-response/m-p/1244577#M125755</link>
      <description>&lt;P&gt;Hie,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Situation - Wanted to kaminsky the DNS Responses for my client from the FW&lt;BR /&gt;Complication - None of the dig are responded&lt;/P&gt;
&lt;P&gt;Need your help on this?&lt;/P&gt;
&lt;P&gt;Client Requests for Promise/Spoofed IP&lt;/P&gt;
&lt;P&gt;keviv@keviv-VMware-Virtual-Platform:~$ ifconfig ens37&lt;BR /&gt;ens37: flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt; mtu 1500&lt;BR /&gt;inet 192.168.21.21 netmask 255.255.255.0 broadcast 192.168.21.255&lt;BR /&gt;inet6 fe80::355a:6e06:90e9:6b84 prefixlen 64 scopeid 0x20&amp;lt;link&amp;gt;&lt;BR /&gt;ether 00:0c:29:80:6e:57 txqueuelen 1000 (Ethernet)&lt;BR /&gt;RX packets 7725 bytes 677203 (677.2 KB)&lt;BR /&gt;RX errors 0 dropped 0 overruns 0 frame 0&lt;BR /&gt;TX packets 7358 bytes 686142 (686.1 KB)&lt;BR /&gt;TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0&lt;/P&gt;
&lt;P&gt;keviv@keviv-VMware-Virtual-Platform:~$ dig @192.168.20.130 fallout.gcc&lt;BR /&gt;;; communications error to 192.168.20.130#53: timed out&lt;BR /&gt;;; communications error to 192.168.20.130#53: timed out&lt;BR /&gt;;; communications error to 192.168.20.130#53: timed out&lt;/P&gt;
&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.18.39-0ubuntu0.24.04.2-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; @192.168.20.130 fallout.gcc&lt;BR /&gt;; (1 server found)&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; no servers could be reached&lt;BR /&gt;keviv@keviv-VMware-Virtual-Platform:~$ dig @192.168.21.20 fallout.gcc&lt;BR /&gt;;; communications error to 192.168.21.20#53: timed out&lt;BR /&gt;;; communications error to 192.168.21.20#53: timed out&lt;BR /&gt;;; communications error to 192.168.21.20#53: timed out&lt;/P&gt;
&lt;P&gt;; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.18.39-0ubuntu0.24.04.2-Ubuntu &amp;lt;&amp;lt;&amp;gt;&amp;gt; @192.168.21.20 fallout.gcc&lt;BR /&gt;; (1 server found)&lt;BR /&gt;;; global options: +cmd&lt;BR /&gt;;; no servers could be reached&lt;BR /&gt;keviv@keviv-VMware-Virtual-Platform:~$&lt;/P&gt;
&lt;P&gt;Firewall Config&lt;/P&gt;
&lt;P&gt;admin@panama# show network dns-proxy astroid&lt;BR /&gt;astroid {&lt;BR /&gt;cache {&lt;BR /&gt;max-ttl {&lt;BR /&gt;enabled no;&lt;BR /&gt;}&lt;BR /&gt;enabled yes;&lt;BR /&gt;}&lt;BR /&gt;tcp-queries {&lt;BR /&gt;enabled no;&lt;BR /&gt;}&lt;BR /&gt;static-entries {&lt;BR /&gt;cachepoisioning {&lt;BR /&gt;address 192.168.20.129;&lt;BR /&gt;domain fallout.gcc;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;interface [ ethernet1/1 ethernet1/2];&lt;BR /&gt;default {&lt;BR /&gt;primary 192.168.20.130;&lt;BR /&gt;}&lt;BR /&gt;enabled yes;&lt;BR /&gt;}&lt;BR /&gt;[edit]&lt;BR /&gt;admin@panama#&lt;/P&gt;
&lt;P&gt;admin@panama&amp;gt; show interface ethernet1/1&lt;BR /&gt;Interface IP address: 192.168.20.130/24&lt;/P&gt;
&lt;P&gt;admin@panama&amp;gt; show interface ethernet1/2&lt;BR /&gt;Interface IP address: 192.168.21.20/24&lt;/P&gt;
&lt;P&gt;admin@panama&amp;gt; show dns-proxy cache name astroid&lt;/P&gt;
&lt;P&gt;Name: astroid&lt;BR /&gt;Cache settings:&lt;BR /&gt;cache-edns: enabled&lt;BR /&gt;entries: 0&lt;BR /&gt;Domain IP/Name Type Class TTL Hits&lt;BR /&gt;-----------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="mailto:admin@panama&amp;gt;" target="_blank"&gt;admin@panama&amp;gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is currently all allow policy ord.&lt;BR /&gt;&lt;BR /&gt;Any suggestions or hint will be welcomed.&amp;nbsp;&lt;BR /&gt;Chao&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 19:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-the-dnsproxy-feature-for-static-response/m-p/1244577#M125755</guid>
      <dc:creator>ocpfn4</dc:creator>
      <dc:date>2025-12-24T19:59:42Z</dc:date>
    </item>
  </channel>
</rss>

