<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN as a DNS Forwarder to resolve External DNS Names in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49208#M36242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking on how to configure DNS proxy on PAN and found below link that provide great information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="3637" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3637"&gt;https://live.paloaltonetworks.com/docs/DOC-3637&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="3522" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3522"&gt;https://live.paloaltonetworks.com/docs/DOC-3522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="4633" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-4633"&gt;https://live.paloaltonetworks.com/docs/DOC-4633&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it does not cover the design that I want for DNS resolution and protect our internal DNS servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I would like to check if anyone has done configuring their internal DNS server to use PAN (DNS Proxy configuration) as a DNS forwarder to resolved all external DNS??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - PAN DNS Proxy will have entry for public DNS server coming from our local ISP server provider at the same time PAN firewall is configured to forward DNS resolution bound for our local domain resolution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Using the above setup, I can protect my internal DNS since all external DNS resolution will be coming from PAN Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any information or ideas are highly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Erwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jul 2014 04:03:32 GMT</pubDate>
    <dc:creator>ErwinBuena</dc:creator>
    <dc:date>2014-07-15T04:03:32Z</dc:date>
    <item>
      <title>PAN as a DNS Forwarder to resolve External DNS Names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49208#M36242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking on how to configure DNS proxy on PAN and found below link that provide great information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="3637" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3637"&gt;https://live.paloaltonetworks.com/docs/DOC-3637&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="3522" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3522"&gt;https://live.paloaltonetworks.com/docs/DOC-3522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2027" data-containertype="14" data-objectid="4633" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-4633"&gt;https://live.paloaltonetworks.com/docs/DOC-4633&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it does not cover the design that I want for DNS resolution and protect our internal DNS servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I would like to check if anyone has done configuring their internal DNS server to use PAN (DNS Proxy configuration) as a DNS forwarder to resolved all external DNS??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - PAN DNS Proxy will have entry for public DNS server coming from our local ISP server provider at the same time PAN firewall is configured to forward DNS resolution bound for our local domain resolution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Using the above setup, I can protect my internal DNS since all external DNS resolution will be coming from PAN Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any information or ideas are highly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Erwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2014 04:03:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49208#M36242</guid>
      <dc:creator>ErwinBuena</dc:creator>
      <dc:date>2014-07-15T04:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: PAN as a DNS Forwarder to resolve External DNS Names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49209#M36243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Few&lt;/SPAN&gt; related discussions for your reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS Proxy -- &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/8699"&gt;https://live.paloaltonetworks.com/thread/8699&lt;/A&gt;&lt;/P&gt;&lt;P&gt;DNS Proxy -- &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/6767"&gt;https://live.paloaltonetworks.com/thread/6767&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/36564"&gt;DNS proxy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2014 06:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49209#M36243</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-15T06:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: PAN as a DNS Forwarder to resolve External DNS Names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49210#M36244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hulk for the feedback&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2014 09:03:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49210#M36244</guid>
      <dc:creator>ErwinBuena</dc:creator>
      <dc:date>2014-07-15T09:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: PAN as a DNS Forwarder to resolve External DNS Names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49211#M36245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure your DHCP to tell your clients to have the internal interface of the firewall as their DNS. Then use DNS Proxy to handle the DNS resolution. You can also deploy a security policy to Deny all dns requests going to the outside (from anyone except the firewall), and only let users resolve DNS if they use your firewall's trust interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2014 22:47:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49211#M36245</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-07-15T22:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: PAN as a DNS Forwarder to resolve External DNS Names</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49212#M36246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi Mivaldi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information. Deploying the PAN internal Interface as the DNS for all DHCP client will not scale out and it's adds up additional time for DNS resolution for internal networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading all the discussion about DNS forwarding in this forum provide me great information including the one that you mention.&lt;/P&gt;&lt;P&gt;1. I've decided to configure our internal DNS server to have a DNS forwarder point to PAN Internal Network for Internet (external) DNS Resolution and query data to our ISP Public DNS.&lt;/P&gt;&lt;P&gt;2. External DNS will only communicating for all DNS resolution via PAN DNS Proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Erwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jul 2014 23:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-as-a-dns-forwarder-to-resolve-external-dns-names/m-p/49212#M36246</guid>
      <dc:creator>ErwinBuena</dc:creator>
      <dc:date>2014-07-15T23:14:23Z</dc:date>
    </item>
  </channel>
</rss>

