<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18870#M13740</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case; the DNS resolvers should be the Palo Alto Firewall.&amp;nbsp; Hence I was thinking of having the mDNS to be allowed by Palo Alto.&amp;nbsp; Makes any sense..?? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2012 09:55:35 GMT</pubDate>
    <dc:creator>kalyanram.piratla</dc:creator>
    <dc:date>2012-05-09T09:55:35Z</dc:date>
    <item>
      <title>Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18866#M13736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;Hi Guys,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;What support does the Palo Alto Firewall offer in terms of forwarding on mDNS (multicast DNS, more specifically Apples Bonjour Service)?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I have a customer where they have the student and staff wireless network on a seperate VLAN, with the Palo Alto Captive Portal as the only route out.&amp;nbsp; Will it require to add a "hardened" apple server to the same network or will the Palo Alto allow to pass the requests through?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;With more iPads wanting to be hooked up to Apple TV or Printing from iPads, I would welcome any potential input or any document you could offer.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Secondly, is there any document on how to configure the DNS proxy available?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Many Thanks,&lt;/P&gt;&lt;P class="MsoNormal"&gt;Kind Regards,&lt;/P&gt;&lt;P class="MsoNormal"&gt;Kalyan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 13:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18866#M13736</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-05-08T13:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18867#M13737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A workaround could be to setup your dhcp server to instruct your wifi clients to use particular dnsservers instead of this mDNS mumbojumbo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you dont have your own resolvers you could use googles at 8.8.8.8 and 8.8.4.4 or some of the public ones provided by opendns.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 13:51:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18867#M13737</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-08T13:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18868#M13738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am sorry; could not understand that in terms of configuration.&amp;nbsp; I assume when you mean DHCP server, it is the DHCP server on the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is; can Palo Alto work as the DNS Server (my experience says NO, but if there was any other way)? because in this case, i am trying to have the Palo as the DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you understand by what I meant...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers..&lt;/P&gt;&lt;P&gt;Kal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 14:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18868#M13738</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-05-08T14:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18869#M13739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the client requests dhcp information some dhcp server on your network will reply (if you use dhcp unless you use static addressing).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know if you run your PA as dhcp server or if you have a dedicated box for this task. Either way you can configure the dhcp server to not only tell the client which ip address to use, which netmask to use and which default gateway to use - but also which dns1 and dns2 the client should use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you dont have your own dns-resolvers on a DMZ or such you can use public dns-servers. Two available (from Google) is one with ip address 8.8.8.8 and one with ip 8.8.4.4 (given that your clients are allowed to reach Internet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you dont need to allow mDNS through your PA device (unless I completely misunderstood your case?).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2012 20:53:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18869#M13739</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-08T20:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18870#M13740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case; the DNS resolvers should be the Palo Alto Firewall.&amp;nbsp; Hence I was thinking of having the mDNS to be allowed by Palo Alto.&amp;nbsp; Makes any sense..?? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 09:55:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18870#M13740</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-05-09T09:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding mDNS (multicast DNS specifically for Apples' Bonjour Service)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18871#M13741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS and mDNS shouldn't be confused. mDNS is a broadcast on that VLAN to specific UDP ports. The broadcast advertises what the client can do; like Screen Sharing or AirPlay. What you're looking for is a Bonjour Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have all your VLANs running through the Palo Alto, you could try creating a multicast rule between the VLANs/Zones with these UDP ports being allowed: 554,54780,62572,5353,5298,5297&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 13:56:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forwarding-mdns-multicast-dns-specifically-for-apples-bonjour/m-p/18871#M13741</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2013-02-13T13:56:36Z</dc:date>
    </item>
  </channel>
</rss>

