<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pan OS 4.1, DNS-Proxy Problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2691#M2005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can change this under Device/Setup/"Service Router Configuration"&lt;/P&gt;&lt;P&gt;Here you can specify the interface to be used for DNS resolution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Nov 2011 12:19:40 GMT</pubDate>
    <dc:creator>Bart_Jocque</dc:creator>
    <dc:date>2011-11-25T12:19:40Z</dc:date>
    <item>
      <title>Pan OS 4.1, DNS-Proxy Problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2690#M2004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hallo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured a PA500 with Pan OS 4.1 wit the WAN interface as DHCP-Client and default route to this interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In DNS-Proxy settings&amp;nbsp; I configured a DNS-Proxy with inherit source the wan if. Primary and secondary DNS is inherited and the dns proxy is aktivated for the internal interface. A firewall rule gives all users access to the dns-proxy for name resolution an the PA is allowed from wan to wan for dns. In traffic monitor I can see, that users gain acces to the dns proxy. But the PA want's to go out for dns resolution with the internal if. So I have to configure a rule to give the internal if access to external. Thats not practicible. At the and I hae to give 25 internal interfaces acces to external DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a second appliance without DHCP on the WAN-interface it works like expected. The PA works realy as a proxy. User have acces to the PA for DNS and the PA gos out for DNS Requests wit his external interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Nov 2011 07:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2690#M2004</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2011-11-25T07:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pan OS 4.1, DNS-Proxy Problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2691#M2005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can change this under Device/Setup/"Service Router Configuration"&lt;/P&gt;&lt;P&gt;Here you can specify the interface to be used for DNS resolution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Nov 2011 12:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2691#M2005</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-11-25T12:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pan OS 4.1, DNS-Proxy Problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2692#M2006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the advise, I changed the interface to use for DNS request as the external one but in the logs, I still can see that the DNS request are from the internal interface (matching the security rule I've created for this purpose, i.e. interface interface to public DNS server).&lt;/P&gt;&lt;P&gt;I am running PAN-OS 4.1.0.&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 10:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-4-1-dns-proxy-problems/m-p/2692#M2006</guid>
      <dc:creator>conglin</dc:creator>
      <dc:date>2011-12-02T10:06:14Z</dc:date>
    </item>
  </channel>
</rss>

