<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS proxy not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/193952#M58084</link>
    <description>&lt;P&gt;I'm assuming your loopback interface is actually in the trust zone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried setting the DNS proxy to use the upstream DNS servers your ISP provides, as they may provide better service than the google ones.&lt;/P&gt;
&lt;P&gt;203.40.0.0/13 appears to be located in Australia, so you may benefit from using DNS closer to your office to prevent running into peering issues&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2018 09:12:24 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-01-05T09:12:24Z</dc:date>
    <item>
      <title>DNS proxy not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/193940#M58083</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;We are currently getting resolve-fail events for DNS.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Failed to resolve domain name: after trying all attempts to name server(s): 8.8.8.8 8.8.4.4&lt;/DIV&gt;&lt;DIV&gt;DNS server is in loopback.2 Interface/Untrust/IP:203.44.x.x&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Below are some pics of DNS proxy settings, session details. Can someone please shed some light what are we missing?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sessiondetails.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13138i6D8AFFF952D450A6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sessiondetails.jpg" alt="sessiondetails.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS Proxy.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13139i0D13FDFF3E17C8E6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DNS Proxy.jpg" alt="DNS Proxy.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Jan 2018 04:52:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/193940#M58083</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2018-01-05T04:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/193952#M58084</link>
      <description>&lt;P&gt;I'm assuming your loopback interface is actually in the trust zone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried setting the DNS proxy to use the upstream DNS servers your ISP provides, as they may provide better service than the google ones.&lt;/P&gt;
&lt;P&gt;203.40.0.0/13 appears to be located in Australia, so you may benefit from using DNS closer to your office to prevent running into peering issues&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 09:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/193952#M58084</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-01-05T09:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/194223#M58133</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;thank you for your response!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually loopback is in the untrust zone. I have checked the admin guide and it does not specify that Interface needs to be in the trust zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please clarify?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 00:41:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/194223#M58133</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2018-01-08T00:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/194261#M58138</link>
      <description>&lt;P&gt;The log you attached shows the source to be an internal IP in the trust zone going out to untrust 8.8.4.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if your dns proxy is on a loopback in the untrust zone, the log you attached does not match your dns proxy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you configure your clients to use the IP of your DNS proxy interface as their DNS server ? For the proxy to work, the clients need to use "the firewall" as their preferred dns server (or the internal DNS needs to use the firewall as it's upstream server)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 09:12:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-not-working/m-p/194261#M58138</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-01-08T09:12:03Z</dc:date>
    </item>
  </channel>
</rss>

