<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic dnsproxy policy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-policy/m-p/36128#M26553</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What allow policy is needed for granting access to the dnsproxy? - when I try and only allow some things like, dns, web-browsing etc. the dnsproxy stops working - and nothing in the logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Nov 2011 21:53:15 GMT</pubDate>
    <dc:creator>felixn</dc:creator>
    <dc:date>2011-11-03T21:53:15Z</dc:date>
    <item>
      <title>dnsproxy policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-policy/m-p/36128#M26553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What allow policy is needed for granting access to the dnsproxy? - when I try and only allow some things like, dns, web-browsing etc. the dnsproxy stops working - and nothing in the logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 21:53:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-policy/m-p/36128#M26553</guid>
      <dc:creator>felixn</dc:creator>
      <dc:date>2011-11-03T21:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: dnsproxy policy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-policy/m-p/36129#M26554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming that you actual DNS server is on another zone and you have configured one of your interface as your DNS proxy, that way to allow the DNS request to go through you would need only dns apart from web-browsing and ssl. Here is the test that I ran, Client is 192.168.59.99 and configured with PAN's interface IP 192.168.59.1 as DNS Proxy , whereas the interface is configured to point 4.2.2.2 as the actual server, here is what the session looks like fro client to the interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;199&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&amp;nbsp; FLOW&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.59.99[56708]/L3-Trust/17&amp;nbsp; (192.168.59.99[56708])vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.59.1[53]/L3-Trust&amp;nbsp; (192.168.59.1[53])&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the session from interface to 4.2.2.2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;193&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&amp;nbsp; FLOW&amp;nbsp; NS&amp;nbsp;&amp;nbsp; 192.168.59.1[58288]/L3-Trust/17&amp;nbsp; (10.30.6.59[22005])vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.2.2.2[53]/L3-Untrust&amp;nbsp; (4.2.2.2[53])&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the sessions are identified as "dns". If you have same setup and you are having issues you should open a support case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khubaib &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 06:32:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-policy/m-p/36129#M26554</guid>
      <dc:creator>kalavi</dc:creator>
      <dc:date>2011-11-09T06:32:21Z</dc:date>
    </item>
  </channel>
</rss>

