<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Benefits of using DNS proxy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27383#M19965</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regarding DNS Sinkhole: This is a new feature, will be available on PAN-OS 6.0.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature adds a new option to the anti-spyware profile, allowing an administrator to enable DNS sinkhole for DNS-based spyware signatures.&amp;nbsp; The user specifies the IPs to sinkhole to, and then the user can run reports on that IP to identify infected hosts.&amp;nbsp; The user can also set the address to the loopback address to effectively cut off the communication.&lt;/P&gt;&lt;P&gt;The sinkhole action, just like the block action for DNS signatures, should be processed before the DNS proxy is processed.&amp;nbsp; Thus, the query never goes through the proxy and sinkhole records are not cached if DNS proxy caching is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS Sinkhole allows administrators to quickly identify infected hosts on the network using DNS traffic.&amp;nbsp; Sinkhole DNS queries involve forging responses to select DNS queries so that clients on the network connect to a specified host rather than the actual host pointed to by DNS.&amp;nbsp; Infected hosts can then be identified from traffic logs and reports.&amp;nbsp; Any hosts that attempt to connect to the sinkholes host (assumed not to be contacted for any legitimate purpose) is infected with malware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding DNS PROXY, please refer below mentioned documents:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4633"&gt;How to Configure DNS Proxy on a Palo Alto Networks Firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/11035"&gt;about&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope above explanation will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Jan 2014 22:25:30 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-01-14T22:25:30Z</dc:date>
    <item>
      <title>Benefits of using DNS proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27382#M19964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Are there any &lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: inherit; text-decoration: underline;"&gt;Security&lt;/SPAN&gt; benefits to using the current implementation of DNS proxy on the PAN? I have seen on the ver 6.0, a new feature called DNS sinkhole, but I don't think it will require the DNS proxy feature. Watchguard checks DNS headers and a couple of other criteria for DNS based attacks, but I don't see anything in PAN documentation that says the PAN Firewall does anything when used a DNS proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 22:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27382#M19964</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2014-01-14T22:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Benefits of using DNS proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27383#M19965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regarding DNS Sinkhole: This is a new feature, will be available on PAN-OS 6.0.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature adds a new option to the anti-spyware profile, allowing an administrator to enable DNS sinkhole for DNS-based spyware signatures.&amp;nbsp; The user specifies the IPs to sinkhole to, and then the user can run reports on that IP to identify infected hosts.&amp;nbsp; The user can also set the address to the loopback address to effectively cut off the communication.&lt;/P&gt;&lt;P&gt;The sinkhole action, just like the block action for DNS signatures, should be processed before the DNS proxy is processed.&amp;nbsp; Thus, the query never goes through the proxy and sinkhole records are not cached if DNS proxy caching is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS Sinkhole allows administrators to quickly identify infected hosts on the network using DNS traffic.&amp;nbsp; Sinkhole DNS queries involve forging responses to select DNS queries so that clients on the network connect to a specified host rather than the actual host pointed to by DNS.&amp;nbsp; Infected hosts can then be identified from traffic logs and reports.&amp;nbsp; Any hosts that attempt to connect to the sinkholes host (assumed not to be contacted for any legitimate purpose) is infected with malware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding DNS PROXY, please refer below mentioned documents:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4633"&gt;How to Configure DNS Proxy on a Palo Alto Networks Firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/11035"&gt;about&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope above explanation will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 22:25:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27383#M19965</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-14T22:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Benefits of using DNS proxy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27384#M19966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information on the sinkhole function. I am using DNS proxy for a "test" environment, so I have set it up and know how it works, but my question is more on whether the PAN includes any security related functionality when using DNS proxy (especially if using reverse DNS proxy) or if this increases security for the environment. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 14:18:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/benefits-of-using-dns-proxy/m-p/27384#M19966</guid>
      <dc:creator>craymond</dc:creator>
      <dc:date>2014-01-15T14:18:15Z</dc:date>
    </item>
  </channel>
</rss>

