<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic DNS URL Redirect Control in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-dns-url-redirect-control/m-p/46982#M34530</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming the URL is known to be malicious, you could implement DNS Sinkholing:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6220"&gt;How to Configure DNS Sinkholing on PAN-OS 6.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An alternative is to set an action of 'block' on your DNS Signature under your Anti-spyware profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I (personally) also like to configure my DNS server to point to OpenDNS servers and add an extra layer of protection (you can get an account with them, they will tie your public IP to the source of the DNS queries and filter those against their database). That means that you will be covered with both PAN-DB and OpenDNS databases for DNS queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Mariano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Aug 2014 23:59:41 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2014-08-05T23:59:41Z</dc:date>
    <item>
      <title>Dynamic DNS URL Redirect Control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-dns-url-redirect-control/m-p/46981#M34529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Most of the "Dynamic DNS" sites are categorized as &lt;STRONG style="color: #333333; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px;"&gt;Computer and Internet Info (PANDB)&lt;/STRONG&gt;.&amp;nbsp; On occasion a device will get infected because of a Dynamic DNS redirect to a malicious site.&amp;nbsp; The initial URL connection is through one of the DDNS sites.&amp;nbsp; Because we allow "Computer and Internet Info", the connection is allowed to the final (malicious) destination.&amp;nbsp; Besides hunting down every DDNS service and creating a custom URL block list - are there any solutions to better control these redirects? Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Aug 2014 19:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-dns-url-redirect-control/m-p/46981#M34529</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2014-08-01T19:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic DNS URL Redirect Control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-dns-url-redirect-control/m-p/46982#M34530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming the URL is known to be malicious, you could implement DNS Sinkholing:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6220"&gt;How to Configure DNS Sinkholing on PAN-OS 6.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An alternative is to set an action of 'block' on your DNS Signature under your Anti-spyware profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I (personally) also like to configure my DNS server to point to OpenDNS servers and add an extra layer of protection (you can get an account with them, they will tie your public IP to the source of the DNS queries and filter those against their database). That means that you will be covered with both PAN-DB and OpenDNS databases for DNS queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Mariano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 23:59:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-dns-url-redirect-control/m-p/46982#M34530</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-08-05T23:59:41Z</dc:date>
    </item>
  </channel>
</rss>

