<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/208409#M61004</link>
    <description>&lt;P&gt;Since PA recommends using 1.1.1.1 for DNS sinkholes I thought it would be interesting for those of us following this practice that Cloudflare is now using 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theverge.com/2018/4/1/17185732/cloudflare-dns-service-1-1-1-1" target="_blank"&gt;https://www.theverge.com/2018/4/1/17185732/cloudflare-dns-service-1-1-1-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Apr 2018 16:06:22 GMT</pubDate>
    <dc:creator>hshawn</dc:creator>
    <dc:date>2018-04-02T16:06:22Z</dc:date>
    <item>
      <title>Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/208409#M61004</link>
      <description>&lt;P&gt;Since PA recommends using 1.1.1.1 for DNS sinkholes I thought it would be interesting for those of us following this practice that Cloudflare is now using 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theverge.com/2018/4/1/17185732/cloudflare-dns-service-1-1-1-1" target="_blank"&gt;https://www.theverge.com/2018/4/1/17185732/cloudflare-dns-service-1-1-1-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 16:06:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/208409#M61004</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-04-02T16:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/208458#M61018</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I was thinking the same thing when I saw the article. Since we only allow our AD servers to go out for DNS resolution and all our clients point internally to the AD servers, its not going to be a big deal for us. We use least privelged deny all allow by exception in our policies. If you allow clients to reach out to external sources for DNS, then use the Palo Alto alternative IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alternatively, you can also use either a Loopback IP (127.0.0.1) or Palo Alto Networks Sinkhole IP (71.19.152.112).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope that helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 19:29:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/208458#M61018</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-04-02T19:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209512#M61252</link>
      <description>&lt;P&gt;For the record, the &lt;A href="https://www.paloaltonetworks.com/documentation/81/pan-os/pan-os/threat-prevention/use-dns-queries-to-identify-infected-hosts-on-the-network/dns-sinkholing" target="_blank"&gt;official recommendation&lt;/A&gt; is to use the predefined provided IP address, or 71.19.152.112, as shown below (predefined IP's may vary depending on your region)&lt;/P&gt;
&lt;P&gt;The occasional 1.1.1.1 showing up in knowledge base articles are basically the author (myself included, i'll admit that) being lazy. We're in the process of cleaning that up though. please don't use 1.1.1.1 &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sinkhole default ip.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14697iF4BC570CFA95A349/image-size/large?v=v2&amp;amp;px=999" role="button" title="sinkhole default ip.png" alt="sinkhole default ip.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 07:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209512#M61252</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-04-11T07:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209562#M61259</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;Thanks for the info. BTW it looks like 71.19.152.112 resolves to prgmr.com. FWIW our predefined is 72.5.65.111&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;side note to anyone alerting on sinkholes from a SEIM if you change the sinkhole IP make sure to change your alert triggers&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 14:44:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209562#M61259</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-04-11T14:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209807#M61305</link>
      <description>&lt;P&gt;As today Palo official sinkhole does not provide any additional benefit (reply to HTTP requests etc) I prefer to use custom IP. Any hard coded IP makes malware easy to identify that it is being fooled by Palo &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 15:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209807#M61305</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-04-12T15:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudflare using 1.1.1.1 (Palo Alto recommended ipv4 DNS sinkhole IP)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209928#M61337</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;you could consider setting up your own honeypot and redirecting any sinkholes there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The predefined sinkhole IP truly discards everything, but is an internet IP so 'smart' malware is less likely to detect it is a false IP (if it checks for private ip DNS replies to identify it is being blackholed)&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2018 08:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cloudflare-using-1-1-1-1-palo-alto-recommended-ipv4-dns-sinkhole/m-p/209928#M61337</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-04-13T08:06:17Z</dc:date>
    </item>
  </channel>
</rss>

