<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conficker DNS Request Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46743#M34359</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any unused ports on the PaloAlto? You could set up a vwire (2 ports) and insert this between the switch and the DNS Proxy. Then you would have the source IP of the machine making the request. One other option would be to configure a mirror port on the switch and configure a single port on the PA as a tap-mode. This will generate alerts but can not block or drop malicious packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Apr 2011 21:18:22 GMT</pubDate>
    <dc:creator>skrall</dc:creator>
    <dc:date>2011-04-14T21:18:22Z</dc:date>
    <item>
      <title>Conficker DNS Request Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46742#M34358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So we have some conficker infections here where I work. The problem is that the PA sits at the edge, so all I see are Conficker DNS Requests that get proxied through our internal DNS Server to the Internet. I guess there is no way that PA can see what IP the original request came from ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any creative thoughts on how to do this ? What I've been doing is starting traces on the DNS Servers and looking for the sources manually. It's a pain. I have ports open. Should I mirror the DNS Server Ports ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 19:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46742#M34358</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2011-04-14T19:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Conficker DNS Request Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46743#M34359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any unused ports on the PaloAlto? You could set up a vwire (2 ports) and insert this between the switch and the DNS Proxy. Then you would have the source IP of the machine making the request. One other option would be to configure a mirror port on the switch and configure a single port on the PA as a tap-mode. This will generate alerts but can not block or drop malicious packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2011 21:18:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46743#M34359</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-04-14T21:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Conficker DNS Request Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46744#M34360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I kind of figured that. I almost wish there was a small agent piece, or a Wireshark filter that could just tell me the sources by monitoring traffic on the machine. I might be able to author one. Getting a mirror port set up where I work could take a while.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Justin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Apr 2011 12:12:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/conficker-dns-request-question/m-p/46744#M34360</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2011-04-15T12:12:50Z</dc:date>
    </item>
  </channel>
</rss>

