<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows DNS Server behind PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36225#M26636</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did a PA install last night, the client had a public facing DNS server. the DNS server had a public IP before we moved it behind PA to nat it. while it was outside firewall with public IP the DNS queries from internet worked fine without any issues. Once we moved it behind PA and gave it static one-to-one nat with proper security policies for dns tcp and udp port 53 then DNS queries from the internet stopped working. I did see traffic hitting the PA and passed to the internet server properly with proper natting but dns would not work. The server also had ftp and web server and those services worked fine from internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Had to move the server back outside the PA to continue service but need to know how to fix this before moving it behind PA again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So quesiton is, what is PA doing differently with DNS? how can I publish Microsoft DNS server running on windows 2003 Server to the internet? I did proper nat and security policies for the IP and port traffic but no luck. Am I missing something? any help would be greatly appreciated. thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;farid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Aug 2013 14:29:20 GMT</pubDate>
    <dc:creator>killerkhan</dc:creator>
    <dc:date>2013-08-02T14:29:20Z</dc:date>
    <item>
      <title>Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36225#M26636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did a PA install last night, the client had a public facing DNS server. the DNS server had a public IP before we moved it behind PA to nat it. while it was outside firewall with public IP the DNS queries from internet worked fine without any issues. Once we moved it behind PA and gave it static one-to-one nat with proper security policies for dns tcp and udp port 53 then DNS queries from the internet stopped working. I did see traffic hitting the PA and passed to the internet server properly with proper natting but dns would not work. The server also had ftp and web server and those services worked fine from internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Had to move the server back outside the PA to continue service but need to know how to fix this before moving it behind PA again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So quesiton is, what is PA doing differently with DNS? how can I publish Microsoft DNS server running on windows 2003 Server to the internet? I did proper nat and security policies for the IP and port traffic but no luck. Am I missing something? any help would be greatly appreciated. thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;farid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 14:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36225#M26636</guid>
      <dc:creator>killerkhan</dc:creator>
      <dc:date>2013-08-02T14:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36226#M26637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just saying "I did proper NAT and security policies" doesn't really help us honestly... do you have screenshots of your rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could possibly try to build an app override for TCP port 53 and UDP port 53 and apply them to the security rule you built, just to rule out the App-ID engine being the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 14:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36226#M26637</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-08-02T14:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36227#M26638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;unortunately I am not on site today to be able to take screen shots or get logs info. but just a general question, is there anything special or specific that needs to be done on PA devices to publish DNS servers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 15:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36227#M26638</guid>
      <dc:creator>killerkhan</dc:creator>
      <dc:date>2013-08-02T15:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36228#M26639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not that I'm aware of honestly... if you allow the App-ID DNS inbound it should "just work" in theory.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 15:15:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36228#M26639</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-08-02T15:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36229#M26640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you suggest allowing &lt;SPAN style="color: #000000; font-family: Tahoma, 'Sans Serif', Arial; font-size: 11px; background-color: #ffffff;"&gt;App-ID DNS&lt;/SPAN&gt; instead of service tcp/udp port 53 inbound?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 15:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36229#M26640</guid>
      <dc:creator>killerkhan</dc:creator>
      <dc:date>2013-08-02T15:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36230#M26641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For what it is worth, I have been running Microsoft DNS servers behind the Palo Alto firewall for quite some time.&amp;nbsp; These are in my DMZ, exposed to the Internet, and allow resolution of a few of our DNS zones.&amp;nbsp; I'm currently running Microsoft server 2012 on these DNS servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto firewall rule is nothing special.&amp;nbsp; It is your typical rule to allow incoming traffic, and allows UDP port 53 as a service.&amp;nbsp; I have application set to any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have manually configured bi-directional NAT so that inbound and outbound traffic all originates from and terminates to the same public IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing that got me when I first setup this up was I forgot to go into the Windows server firewall rules and allow DNS from networks other than the one the server was on. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 18:14:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36230#M26641</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2013-08-02T18:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36231#M26642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;App-ID DNS and "application default" for the service should let DNS in... at least I've not seen PA mis-identify DNS traffic in the past for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 19:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36231#M26642</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-08-02T19:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36232#M26643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just came across this... &lt;A href="http://support.microsoft.com/kb/828263" title="http://support.microsoft.com/kb/828263"&gt;http://support.microsoft.com/kb/828263&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if this was causing the problems. will try it in next maintenance window&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 19:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36232#M26643</guid>
      <dc:creator>killerkhan</dc:creator>
      <dc:date>2013-08-02T19:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36233#M26644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi KillerKhan,&lt;/P&gt;&lt;P&gt;&amp;nbsp; did you fix your issue? I am facing your same problem with an infoblox device I need to publish behind a PAVM via PAT on dns53UDP.&lt;/P&gt;&lt;P&gt;Despite I did the right rule, no dns traffic is redirected to the PAN interface...&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;walter doria&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Nov 2014 17:24:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36233#M26644</guid>
      <dc:creator>paloalto_exn</dc:creator>
      <dc:date>2014-11-23T17:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36234#M26645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You should have no problem, you probably misconfigured a NAT rule or the associated Security rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; You should try not to use a Bi-direction NAT but 2 NAT rules and double check your Security rule (remember the trick for destination NATs).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2014 10:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36234#M26645</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2014-11-24T10:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DNS Server behind PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36235#M26646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;probably not but if you want the traffic logs will show bytes sent&amp;nbsp; / recv sizes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;more than likely a nat misconfiguration. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2014 17:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-dns-server-behind-pa/m-p/36235#M26646</guid>
      <dc:creator>jkim2</dc:creator>
      <dc:date>2014-12-01T17:01:33Z</dc:date>
    </item>
  </channel>
</rss>

