<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering and DNS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40497#M29740</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...URL Filtering is applied to web browsing traffic and not to DNS requests.&amp;nbsp; In PAN-OS 5.x, DNS botnet signatures are supported as part of the threat prevention license.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Mar 2013 20:58:15 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2013-03-14T20:58:15Z</dc:date>
    <item>
      <title>URL Filtering and DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40496#M29739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to figure out if the URL Filtering detects domians in DNS requests and can take actions based on a domain in a DNS request (ie. blocking). I would like to move some of my DNS sinkhole activity to the Palo Alto 5020, but i'm unsure if this is a viable option with URL filtering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;-sc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 19:55:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40496#M29739</guid>
      <dc:creator>susan_collins</dc:creator>
      <dc:date>2013-03-14T19:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering and DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40497#M29740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...URL Filtering is applied to web browsing traffic and not to DNS requests.&amp;nbsp; In PAN-OS 5.x, DNS botnet signatures are supported as part of the threat prevention license.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 20:58:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40497#M29740</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-03-14T20:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering and DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40498#M29741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Rmonvon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know if DNS sinkholing can be implemented on the Palos? Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-sc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 21:52:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40498#M29741</guid>
      <dc:creator>susan_collins</dc:creator>
      <dc:date>2013-03-14T21:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering and DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40499#M29742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As already mentioned the URL filtering is based on the the contents of the actual http request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However in PA there is also a DNS-proxy feature which I think might be able to be used to sinkhole various domains, see some info in &lt;A __default_attr="4604" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The admin guide has a better description regarding settings of the dns-proxy feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion the best option is to use your own dns-servers (place in DMZ) and perform the sinkholing in them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Mar 2013 07:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filtering-and-dns/m-p/40499#M29742</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-15T07:47:52Z</dc:date>
    </item>
  </channel>
</rss>

