<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Proxy Errors in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18935#M13788</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The above errors are due to a delayed response from the DNS server.&amp;nbsp; There is an error processing the response packet from the dns server because the entry has already been cleared out to the tables.&amp;nbsp; Try to use a server that has a faster response time to clear this up.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:21:54 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:38:40 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1320): [20840/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:20840&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:38:40 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[20840] entry is already freed!&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:38:40 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;If this was due to bursty traffic and the buffers were becoming depleted you would most likely get the following error:&amp;nbsp; &lt;SPAN style="font-size: 10pt; line-height: 1.5em; color: #575757; font-family: arial, helvetica, sans-serif;"&gt;Error: sendfromto(pan_dnsproxy_util.c:378): sendmsg (No buffer &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em; color: #575757; font-family: arial, helvetica, sans-serif;"&gt;space available)&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 28 Sep 2013 00:29:06 GMT</pubDate>
    <dc:creator>nayubi</dc:creator>
    <dc:date>2013-09-28T00:29:06Z</dc:date>
    <item>
      <title>DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18930#M13783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a remote office using a PA-200 in the middle east. I configured it to use DNS proxy with caching to lower the time for resolution over the VPN tunnel back to our corporate DNS servers in the US. We also have intermittent disconnects due to the unreliable internet connection there and this seemed to help eliminate some of the complaints of network connectivity problems. At any rate, I am receiving possibly thousands of errors in the system logs related to DNS proxy. Here is just 3 lines of it:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2013-09-24 at 9.12.26 AM.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8527_Screen Shot 2013-09-24 at 9.12.26 AM.png" style="width: 620px; height: 83px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a screenshot of my config. I also have a bunch of static entries under that tab and nothing under proxy rules.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2013-09-24 at 9.14.13 AM.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8534_Screen Shot 2013-09-24 at 9.14.13 AM.png" style="width: 620px; height: 344px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that things are resolving fine, however. From a Windows 8 VM, configured to use the DNS proxy only doesn't seem to be having any problems. Any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 15:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18930#M13783</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-09-24T15:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18931#M13784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please attach the output for the following command in a notepad file:&lt;/P&gt;&lt;P&gt;&amp;gt; tail lines 1000 mp-log dnsproxyd.log&lt;/P&gt;&lt;P&gt;&amp;gt; debug dnsproxyd show connections&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully, dnsproxyd.log gives us some valuable information about those failed resolutions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 15:55:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18931#M13784</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-24T15:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18932#M13785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tail lines shows the following around 3:10 on 9/24:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sep 24 02:57:21 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Sep 24 04:21:52 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1320): [9951/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:9951&lt;/P&gt;&lt;P&gt;Sep 24 04:21:52 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[9951] entry is already freed!&lt;/P&gt;&lt;P&gt;Sep 24 04:21:52 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Sep 24 04:21:54 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1320): [5461/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:5461&lt;/P&gt;&lt;P&gt;Sep 24 04:21:54 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[5461] entry is already freed!&lt;/P&gt;&lt;P&gt;Sep 24 04:21:54 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Sep 24 04:38:40 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1320): [20840/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:20840&lt;/P&gt;&lt;P&gt;Sep 24 04:38:40 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[20840] entry is already freed!&lt;/P&gt;&lt;P&gt;Sep 24 04:38:40 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug shows "no pending connections". I tried to initiate connections but I received the same results.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 17:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18932#M13785</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-09-24T17:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18933#M13786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for providing the details regarding &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;dnsproxyd. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;This issue could be related to bursty DNS &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;response&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt;"&gt;&lt;SPAN style="line-height: 1.5em;"&gt; &lt;/SPAN&gt;&lt;SPAN style="line-height: 19.5px;"&gt;received&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em;"&gt; from the server, which would clog the buffer space available for DNS. This calls for a live troubleshooting session and in-depth tech support analysis - to see if a high rate would cause buffer depletion leading to dropped packets from the server side.&amp;nbsp; I was able to look up couple of similar existing cases which are still being investigated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;At this point, opening a case through support portal would be the best way to tackle your issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Kunal Adak&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 19:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18933#M13786</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-24T19:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18934#M13787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the requests are very high, using alternative DNS like BIND can be a good option here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed R Hasnain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 20:06:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18934#M13787</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2013-09-24T20:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18935#M13788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The above errors are due to a delayed response from the DNS server.&amp;nbsp; There is an error processing the response packet from the dns server because the entry has already been cleared out to the tables.&amp;nbsp; Try to use a server that has a faster response time to clear this up.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:21:54 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:38:40 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1320): [20840/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:20840&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:38:40 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[20840] entry is already freed!&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Sep 24 04:38:40 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;If this was due to bursty traffic and the buffers were becoming depleted you would most likely get the following error:&amp;nbsp; &lt;SPAN style="font-size: 10pt; line-height: 1.5em; color: #575757; font-family: arial, helvetica, sans-serif;"&gt;Error: sendfromto(pan_dnsproxy_util.c:378): sendmsg (No buffer &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em; color: #575757; font-family: arial, helvetica, sans-serif;"&gt;space available)&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Sep 2013 00:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18935#M13788</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2013-09-28T00:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18936#M13789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any ideas on how to resolve the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Palo Alto support is suggesting some type of vulnerability and traffic is being cut off. I don't see anything, at all, in the threat logs. It's suggested I remove the vulnerability profile from the security policy DNS traffic is using but if the threat logs don't show anything it doesn't seem like that would do the trick. Plus, I would be opening my network up to vulnerabilities. I would create an exception before completely removing a vulnerability profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 20:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18936#M13789</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2013-09-30T20:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy Errors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18937#M13790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The logs indicate the server is slow to respond to the requests and they are being aged out.&amp;nbsp; This can only be fixed by response times, weather hardware upgrade, or adding additional servers, etc.&amp;nbsp; If you have multiple servers you may try and load balance between them by domains to lighten the load.&amp;nbsp; You can also enable caching on the advanced tab.&amp;nbsp; Around how many requests are you trying to proxy for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your server should be responding back to the pan dns requests via the management unless configured with a service route.&amp;nbsp; What is the vulnerability that this traffic is being seen as and on what interface and zone and direction is it seen coming from?&amp;nbsp; Is it the server or client traffic being identified as the threat.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 02:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-errors/m-p/18937#M13790</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2013-10-02T02:05:16Z</dc:date>
    </item>
  </channel>
</rss>

