<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Proxy - Can I use it to resolve all outbound in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6474#M4735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am&amp;nbsp; having the same issue, even though the local domain names have been setup and dns servers for these domains have been specified, all traffic that should have gone to the internal dns servers is sent to the internet dns servers instead. We are running pan-os 4.05. Static and internetaddresses are resolved correctly, but local addresses are not (non existent domain or internet values for A records, instead of local values)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Sep 2011 12:21:28 GMT</pubDate>
    <dc:creator>seniornwb</dc:creator>
    <dc:date>2011-09-27T12:21:28Z</dc:date>
    <item>
      <title>DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6464#M4725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I use the DNS Proxy to resolve all of my outbound DNS queries?&lt;/P&gt;&lt;P&gt;I would like to point my inside DNS servers to the Palo Alto firewall and then let the firewall resolve the DNS query.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 17:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6464#M4725</guid>
      <dc:creator>bwaaso</dc:creator>
      <dc:date>2011-04-04T17:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6465#M4726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can&lt;/P&gt;&lt;P&gt;For this to work you would only need to create a new dns proxy, connect it to an interface and configure its primary and secondary upstream DNS servers. Then you would need to point your internal DNS server to the internal IP of the (L3) interface and make sure a security policy allows connection from the inside to the internal interface and from the external interface to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take note it will require upstream DNS servers, the proxy can't do root lookups on its own&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 08:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6465#M4726</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-04-05T08:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6466#M4727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do I allow the inside interface to accecpt DNS requests?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 14:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6466#M4727</guid>
      <dc:creator>bwaaso</dc:creator>
      <dc:date>2011-04-05T14:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6467#M4728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;firstly by enabling DNS proxy and secondly verifying your rulebase: in the default rulebase this will be automatically accepted, if you have a drop rule at the end of your rulebase for "any", this will be denied so you will need to create a rule that accepts dns queries to the firewall's interface IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 15:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6467#M4728</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-04-05T15:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6468#M4729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, are you saying that if I am using PA firewalls as my edge authoritative DNS server I couldn't point it to a list of root servers for external lookups for example?&amp;nbsp; Is this done by design?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 18:01:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6468#M4729</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-04-05T18:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6469#M4730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the proxy dns was designed as a stub resolver so it is able to bend certain dns queries to an alternative dns server of your choice and have all the other dns entries handled by an upstream DNS server (recursor)&lt;/P&gt;&lt;P&gt;it will also not be able to handle as authoritative as we don't hold zones, we forward depending on the query&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 10:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6469#M4730</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-04-06T10:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6470#M4731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are trying to do exactly the same thing : we setup a DNS proxy which has to send all DNS requests to the Internet except those for our own domain ( let say mydomain.com ), but all DNS requests are sent to internet !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup is the following in the PAN setup box :&lt;/P&gt;&lt;P&gt;- primary and secondary DNS are set to point to Internet DNS.&lt;/P&gt;&lt;P&gt;- We add a DNS rule : mydomain.com =&amp;gt; our DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything special to do for this feature to work as expected, syntax or whatever ? We are running PAN OS 4.0.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 04:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6470#M4731</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-09-09T04:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6471#M4732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you do it the other way? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have your clients point to the internal DNS server. Configure the DNS server to forwards all other requests to the PAN interface hosting the DHCP Proxy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 17:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6471#M4732</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2011-09-14T17:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6472#M4733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your proposal, but actualy, it's for DMZ servers. They have to request both internal and outside DNS servers. We don't have any DNS forwarding setup on our internal DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN split DNS does not works &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 04:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6472#M4733</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-09-15T04:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6473#M4734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It can work the way you want it to.I have quite a few DNS Proxy rules setup. In the rule I have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domainname.com&lt;/P&gt;&lt;P&gt;*.domainname.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all forwarding to the Internal DNS servers. Everything else goes to an ISP DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest you use CLI scripting if you have a bunch of internal domains to import.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 18:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6473#M4734</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2011-09-16T18:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6474#M4735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am&amp;nbsp; having the same issue, even though the local domain names have been setup and dns servers for these domains have been specified, all traffic that should have gone to the internal dns servers is sent to the internet dns servers instead. We are running pan-os 4.05. Static and internetaddresses are resolved correctly, but local addresses are not (non existent domain or internet values for A records, instead of local values)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 12:21:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6474#M4735</guid>
      <dc:creator>seniornwb</dc:creator>
      <dc:date>2011-09-27T12:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6475#M4736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry to say that, but i'm pleased to see we are not alone with this issue.&lt;/P&gt;&lt;P&gt;We'll open a case.&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 14:01:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6475#M4736</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-09-27T14:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy - Can I use it to resolve all outbound</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6476#M4737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you receive a reply from PA about the case yet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Hen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 12:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-can-i-use-it-to-resolve-all-outbound/m-p/6476#M4737</guid>
      <dc:creator>seniornwb</dc:creator>
      <dc:date>2011-10-14T12:30:47Z</dc:date>
    </item>
  </channel>
</rss>

