<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FQDN and DNS failure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31185#M22813</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If im not mistaken FQDN rules are resolved when the ruleset is committed and not dynamically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note that the ruleset can be automatically committed if you have "download-and-apply" threat preventation and/or url-category database updates (usually once or twice a day).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generelly its bad to use FQDN for firewalls mainly because you will then rely on some external information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us assume you setup a rule which looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srcip: any&lt;BR /&gt;srcport: &amp;gt;1023&lt;BR /&gt;dstip: mail.example.com&lt;BR /&gt;dstport: any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then let us assume someone dns poision the dns-server your firewall is using when committing the rules so mail.example.com resolves into "0.0.0.0" (or even worse hacks your dns-server to manually setup the zones). Or for that matter if the dns-server is unavailable when you commits the ruleset - is the default in the firewall "0.0.0.0" for unresolved addresses or is it "255.255.255.255" (or will it even commit)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result would then be that you allow the current port and/or app-id to EVERY ip-address available for that particular zone (or even worse if you select zone:any).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to setup rules towards your email servers we can be pretty sure you already use static ip's for those servers and therefor your have another reason for why you shouldnt use FQDN (because there is simply no need to).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can setup local names in the firewall if you go to Network -&amp;gt; Address objects (and even Address Groups) to setup stuff like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address objects:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail1.example.com (1.1.1.1)&lt;BR /&gt;mail2.example.com (2.2.2.2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mailservers (mail1.example.com, mail2.example.com)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above will point to the address objects named mail1. and mail2. NOT the FQDN). Or if you think you could be confused if its FQDN or not then just:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address objects:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail1 (1.1.1.1)&lt;BR /&gt;mail2 (2.2.2.2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mailservers (mail1, mail2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then setup the rule as (just an example, in real life one would choose designated port along with zone AND app-id etc):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srcip: any&lt;BR /&gt; srcport: &amp;gt;1023&lt;BR /&gt; dstip: Mailservers&lt;BR /&gt; dstport: any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Jan 2012 22:40:19 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-01-26T22:40:19Z</dc:date>
    <item>
      <title>FQDN and DNS failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31184#M22812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking to use FQDNs inside Address Objects but have some reservations.&amp;nbsp; What happens if my DNS goes down, or becomes corrupted for some reason.&amp;nbsp; In other words, when using FQDNs, what happens if the PA can't resolve the address?&amp;nbsp; Is all traffic to FQDN configured objects blocked? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an example, let's say access to my DNS server (or some other critical device) is through a rule with an address object of FQDN and not IP.&amp;nbsp; Since I know the IP address of my DNS server, would I be able to SSH to it through an IP call or am I totally blocked until DNS comes back online?&amp;nbsp; If true, I would need a separate rule to allow traffic by IP Netmask to my DNS server just in case DNS goes down and I need to gain access to my server to troubleshoot any problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another example would be use FQDN for my email servers.&amp;nbsp; If DNS goes missing, does all email stop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bart&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 22:05:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31184#M22812</guid>
      <dc:creator>blwallace</dc:creator>
      <dc:date>2012-01-26T22:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN and DNS failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31185#M22813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If im not mistaken FQDN rules are resolved when the ruleset is committed and not dynamically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note that the ruleset can be automatically committed if you have "download-and-apply" threat preventation and/or url-category database updates (usually once or twice a day).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generelly its bad to use FQDN for firewalls mainly because you will then rely on some external information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us assume you setup a rule which looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srcip: any&lt;BR /&gt;srcport: &amp;gt;1023&lt;BR /&gt;dstip: mail.example.com&lt;BR /&gt;dstport: any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then let us assume someone dns poision the dns-server your firewall is using when committing the rules so mail.example.com resolves into "0.0.0.0" (or even worse hacks your dns-server to manually setup the zones). Or for that matter if the dns-server is unavailable when you commits the ruleset - is the default in the firewall "0.0.0.0" for unresolved addresses or is it "255.255.255.255" (or will it even commit)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result would then be that you allow the current port and/or app-id to EVERY ip-address available for that particular zone (or even worse if you select zone:any).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to setup rules towards your email servers we can be pretty sure you already use static ip's for those servers and therefor your have another reason for why you shouldnt use FQDN (because there is simply no need to).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can setup local names in the firewall if you go to Network -&amp;gt; Address objects (and even Address Groups) to setup stuff like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address objects:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail1.example.com (1.1.1.1)&lt;BR /&gt;mail2.example.com (2.2.2.2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mailservers (mail1.example.com, mail2.example.com)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above will point to the address objects named mail1. and mail2. NOT the FQDN). Or if you think you could be confused if its FQDN or not then just:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address objects:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail1 (1.1.1.1)&lt;BR /&gt;mail2 (2.2.2.2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mailservers (mail1, mail2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then setup the rule as (just an example, in real life one would choose designated port along with zone AND app-id etc):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srcip: any&lt;BR /&gt; srcport: &amp;gt;1023&lt;BR /&gt; dstip: Mailservers&lt;BR /&gt; dstport: any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 22:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31185#M22813</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-01-26T22:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN and DNS failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31186#M22814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I understand you correctly, the FQDN in regards to function, is really an alias - meaning, the FQDN is resolved at rule commit and the firewall then holds the IP address of the resolve action to manage the traffic defined within the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your example, mail1.example.com is a FQDN, but you state the firewall uses 1.1.1.1 as the real address of the object and not an nslookup each time the rule is hit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 23:02:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31186#M22814</guid>
      <dc:creator>blwallace</dc:creator>
      <dc:date>2012-01-26T23:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN and DNS failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31187#M22815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you setup an address object such as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail1 (mail1.example.com)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and use this in a rule the FQDN will be resolved during commit and the ip address which mail1.example.com points to according to the dns-server used will be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You click commit&lt;/P&gt;&lt;P&gt;2) The PAN will replace the names of each address object with the&amp;nbsp; content each address object refers to (mail1.example.com for above example).&lt;/P&gt;&lt;P&gt;3) Next the PAN detects that you use FQDN so it will need to resolve mail1.example.com (lets say into 1.2.3.4) by query your dns-server.&lt;/P&gt;&lt;P&gt;4) The PAN will (hidden from you) "rewrite" the rule so "1.2.3.4" will be actually written to the hardware (FPGA's).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, if you use address objects which points to ip-addresses (instead of FQDN) there is no need to query external dns-server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Address object:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail1 (1.1.1.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During commit the following will then happen:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You click commit.&lt;/P&gt;&lt;P&gt;2) The PAN will replace the names of each address object with the content each address object referes to (1.1.1.1 for above example).&lt;/P&gt;&lt;P&gt;3) Since you have no FQDN's at this stage the PAN wont need to perform any dns-queries.&lt;/P&gt;&lt;P&gt;4) The PAN will (hidden from you) "rewrite" the rule so "1.1.1.1" will be actually written to the hardware (FPGA's).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 23:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31187#M22815</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-01-26T23:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN and DNS failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31188#M22816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 15:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-and-dns-failure/m-p/31188#M22816</guid>
      <dc:creator>blwallace</dc:creator>
      <dc:date>2012-01-27T15:29:18Z</dc:date>
    </item>
  </channel>
</rss>

