<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS service route doesn't work ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26075#M19026</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having troubles configuring dns service route for DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS servers are behind tagged internal interface of PA-2050 device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to configure that for syslog and it sends all the traffic PA outbound to the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to do the same with DNS, but when I do, PA stops sending queries either through management interface or through the interface the routing to dns servers is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not using dnsproxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this enough information for any help ?&lt;/P&gt;&lt;P&gt;Any options, what should I try ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Pawel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Sep 2013 01:41:08 GMT</pubDate>
    <dc:creator>pawel_stankiewicz</dc:creator>
    <dc:date>2013-09-24T01:41:08Z</dc:date>
    <item>
      <title>DNS service route doesn't work ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26075#M19026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having troubles configuring dns service route for DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS servers are behind tagged internal interface of PA-2050 device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to configure that for syslog and it sends all the traffic PA outbound to the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to do the same with DNS, but when I do, PA stops sending queries either through management interface or through the interface the routing to dns servers is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not using dnsproxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this enough information for any help ?&lt;/P&gt;&lt;P&gt;Any options, what should I try ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Pawel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 01:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26075#M19026</guid>
      <dc:creator>pawel_stankiewicz</dc:creator>
      <dc:date>2013-09-24T01:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNS service route doesn't work ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26076#M19027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pawel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to ping the DNS servers from the Palo Alto firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if you are using an interface other than the management interface (example Ethernet1/2), are you able to ping from Ethernet1/2's ip address to the DNS server? OR, if you are using default configuration (i.e management interface), can you ping from the management interface to the DNS servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the DNS servers configured under Device&amp;gt; Setup &amp;gt; Services - are those internal or external?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 13:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26076#M19027</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-24T13:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS service route doesn't work ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26077#M19028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see any thing in the traffic logs or threat logs regarding DNS traffic on the PAN being dropped ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed R Hasnain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 13:42:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26077#M19028</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2013-09-24T13:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS service route doesn't work ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26078#M19029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pawel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are configuring service routes for reaching to DNS server through any other interface other than management interface yes we do it as shown in below image.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="dns-test.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8526_dns-test.PNG.png" style="width: 620px; height: 317px;" /&gt;&lt;/P&gt;&lt;P&gt;I have highlighted on left for DNS, we generally select another interface on PAN to pass traffic. In your case seems like this is not working neither the management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps to ensure:&lt;/P&gt;&lt;P&gt;1&amp;gt; Do source ping:&lt;/P&gt;&lt;P&gt;ping source &amp;lt;New interface IP configured on service route&amp;gt; host &amp;lt;Dns server IP&amp;gt;&lt;/P&gt;&lt;P&gt;If configured right it has to send out pings and we can see outcome. &lt;/P&gt;&lt;P&gt;2&amp;gt; We can take packet captures on PAN for new interface configured for DNS traffic to pass through and instantly we can see data on the captures, if we do not see then PAN is not passing.&lt;/P&gt;&lt;P&gt;Based on the captures we may know that if the Dns server if received dns packets from PAN did it respond back or not.&lt;/P&gt;&lt;P&gt;3&amp;gt; Also in the above image on the right you can select custom values as shown.&lt;/P&gt;&lt;P&gt;Indicate the DNS server IP in destination field and source address as the new interface IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope these steps should narrow down the issue.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Sep 2013 15:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26078#M19029</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-09-24T15:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS service route doesn't work ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26079#M19030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank All for help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the late reply.&lt;/P&gt;&lt;P&gt;It turned out firewall itself blocked access to dns-es as there was no security rule for that.&lt;/P&gt;&lt;P&gt;In fact, this was not obvious as I put a rule for that but somehow it didn't work. I've just opened wide access from "all" zones to dnses and it started to work. Maybe that should be narrowed, but as I'm fighting with other pcularities it was no time to debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Pawel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Nov 2013 01:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-service-route-doesn-t-work/m-p/26079#M19030</guid>
      <dc:creator>pawel_stankiewicz</dc:creator>
      <dc:date>2013-11-28T01:08:54Z</dc:date>
    </item>
  </channel>
</rss>

