<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you have multiple DNS Sink in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126566#M46524</link>
    <description>&lt;P&gt;I have a question about DNS sink hole in the corporate enivorment.&lt;/P&gt;&lt;P&gt;If you have multiple DNS servers and multiple Palo Altos firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you configure palo alto firewalls to work with all the dns servers?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have to setup each firewall with different sink hole zones or same zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The OS is 7.1&lt;/P&gt;&lt;P&gt;Any help with would be great on this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Nov 2016 22:18:59 GMT</pubDate>
    <dc:creator>AdamCoombs</dc:creator>
    <dc:date>2016-11-15T22:18:59Z</dc:date>
    <item>
      <title>Can you have multiple DNS Sink</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126566#M46524</link>
      <description>&lt;P&gt;I have a question about DNS sink hole in the corporate enivorment.&lt;/P&gt;&lt;P&gt;If you have multiple DNS servers and multiple Palo Altos firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you configure palo alto firewalls to work with all the dns servers?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have to setup each firewall with different sink hole zones or same zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The OS is 7.1&lt;/P&gt;&lt;P&gt;Any help with would be great on this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 22:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126566#M46524</guid>
      <dc:creator>AdamCoombs</dc:creator>
      <dc:date>2016-11-15T22:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have multiple DNS Sink</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126587#M46525</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;A DNS sinkhole is 'fake'&amp;nbsp;IP so make sure you are not using it, the example shows 1.1.1.1. The zone doesnt really matter ,what matters is that your traiffic policy has the Anti-Spyware settings. It will need to be setup on each cluster or standable PAN's you have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 23:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126587#M46525</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-11-15T23:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have multiple DNS Sink</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126833#M46555</link>
      <description>&lt;P&gt;I have read this information, but just wanting to verify that if I have two different palo altos devices that can route between each other that will not cause a issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So here is a example I want to make sure will work&lt;/P&gt;&lt;P&gt;Palo Alto A sinkhole ip address 2.2.2.2 &amp;nbsp;DNS server 10.0.0.1, 10.0.0.2&lt;/P&gt;&lt;P&gt;Palo Alto B sinkhole ip address 3.3.3.3 &amp;nbsp;DNS server 10.10.0.1, 10.10.0.2&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto A will block bad dns requested from 10.0.0.1, 10.0.0.2 and 10.10.0.1, 10.10.0.2&lt;/P&gt;&lt;P&gt;Same thing on Palo Alto B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look at logs in threats area I see sinkhole on both palo alto's&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 20:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126833#M46555</guid>
      <dc:creator>AdamCoombs</dc:creator>
      <dc:date>2016-11-16T20:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have multiple DNS Sink</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126984#M46575</link>
      <description>&lt;P&gt;DNS sinkhole on PA&amp;nbsp;simply checks every DNS request going through rule with specific&amp;nbsp;anti-spyware profile (doesn't matter from which server, PC or whatever device) and replaces DNS response with fake IP in cases where domain is recognised as suspicious or malware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, on different FWs you can have different IPs as sinkhole. In fact you can also have different IPs as sinkhole in diferent anti-spyware profiles on same device. Though I don't really see a benefit of different IPs as sinkhole.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 09:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126984#M46575</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-17T09:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have multiple DNS Sink</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126985#M46576</link>
      <description>&lt;P&gt;If you already had suspicious DNS queries on block you can't cause any issue with changing to sinkhole. If you had them on alert or allow till now you will now disrupt&amp;nbsp;these queries (with fake IP) and i guess you risk false positives. But so far I haven't seen a false positive with suspicious DNS queries yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 09:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/126985#M46576</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-17T09:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have multiple DNS Sink</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/127064#M46583</link>
      <description>&lt;P&gt;That is what I thought too santonic, I need to check with someone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not know you could set different Fake IP address on different DNS sink profiles nice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 14:45:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-have-multiple-dns-sink/m-p/127064#M46583</guid>
      <dc:creator>AdamCoombs</dc:creator>
      <dc:date>2016-11-17T14:45:57Z</dc:date>
    </item>
  </channel>
</rss>

