<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNSproxy resolve fail msgs - only I am not using this feature! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209798#M61302</link>
    <description>&lt;P&gt;Did this begin after an 8.1.0 update ?&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2018 15:19:15 GMT</pubDate>
    <dc:creator>dbjohnson</dc:creator>
    <dc:date>2018-04-12T15:19:15Z</dc:date>
    <item>
      <title>DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/208275#M60971</link>
      <description>&lt;P&gt;I'm getting system log errors that state " failed to resolve domain... etc" and lists the dnsproxy as the type and resolve-fail as the event. This is all really cool - but I have NOT set DNS proxy up - ever. If I dig through the logs - I can see a time where "Dnsproxy object:mgmt-obj was enabled" - however I do not know why it would state so as I can find no config changes made that would correleate and and my current running config shows no DNS proxy's have been set up ( enabled or otherwise).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else seen this?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 16:57:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/208275#M60971</guid>
      <dc:creator>craiglunt</dc:creator>
      <dc:date>2018-03-30T16:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209798#M61302</link>
      <description>&lt;P&gt;Did this begin after an 8.1.0 update ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 15:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209798#M61302</guid>
      <dc:creator>dbjohnson</dc:creator>
      <dc:date>2018-04-12T15:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209818#M61306</link>
      <description>&lt;P&gt;Actually - Yes - known bug?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 16:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209818#M61306</guid>
      <dc:creator>craiglunt</dc:creator>
      <dc:date>2018-04-12T16:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209830#M61310</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38929"&gt;@craiglunt&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You could be running into PAN-92972&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 16:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209830#M61310</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-12T16:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209831#M61311</link>
      <description>&lt;P&gt;Can't seem to find a reference to that issue anywhere. can you elucidate? Thanks&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38929"&gt;@craiglunt&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You could be running into PAN-92972&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 17:08:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209831#M61311</guid>
      <dc:creator>craiglunt</dc:creator>
      <dc:date>2018-04-12T17:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209877#M61328</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38929"&gt;@craiglunt&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Actually I just re-read what you intially posted, ignore the bug-id I presented (I'm not sure it's public yet, and I'm not sure if I could give you the description if it isn't seeing as I found it on a walled off resource).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's actually normal to see system events with a subtype of dnsproxy, pretty much everyone should be seeing them if they look for it. Regardless of the dns-proxy configuration the dameon is used internally by the firewall for different dns functions. I know that panagent had wrote something about it that I'll try to find again, unfortuantely I haven't seen anything posted by them in while so I'm not sure they are still active to expand on it at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 20:21:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209877#M61328</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-12T20:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209882#M61330</link>
      <description>&lt;P&gt;I have a few devices upgraded to 8.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Prior to the upgrade - we would get the resolve error on some FQDN object entries blocked, but this was due to dead domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading to 8.1, the errors started&amp;nbsp;due to Server Monitor entries,&amp;nbsp; for network addresses input as FQDN. We do not run DNS proxy profiles on our appliances either, but did attempt doing so to see if the problem would resolve. Having the DNS proxy, rather than global DNS for the mgmt interface, did not make a difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 20:32:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209882#M61330</guid>
      <dc:creator>dbjohnson</dc:creator>
      <dc:date>2018-04-12T20:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209887#M61331</link>
      <description>&lt;P&gt;This seems to have stopped for me - (at least temporarily). not sure why ... will continue to check as I do not like inconsistencies - especially in a fw and more so when it involves dns.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 21:03:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/209887#M61331</guid>
      <dc:creator>craiglunt</dc:creator>
      <dc:date>2018-04-12T21:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/210614#M61507</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I'm seeing a lot of these too after 8.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i can ping the dns name from the panos cli... not sure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to resolve domain name:ad1.our.internal after trying all attempts to name server(s): internal.dns.ip.address 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 23:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/210614#M61507</guid>
      <dc:creator>LCMember3055</dc:creator>
      <dc:date>2018-04-17T23:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/210724#M61515</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/33359"&gt;@LCMember3055&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;8.1 is really where I started to pay attention to them simply because I'm seeing it come across a lot more in the logs. I passed the information back to TAC and haven't really heard anything outside of the fact that they are still investigating the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 12:47:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/210724#M61515</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-18T12:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/211891#M61783</link>
      <description>&lt;P&gt;&amp;nbsp;I think I figured this out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a default internal dns-proxy object called mgmt-obj that works to resolve hostnames when you check the "resolve hostname" checkbox in the various monitor logs.&amp;nbsp; To do this it does a reverse dns lookup using the arpa database - and sends a dns query for a pointer record of the domain name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ie - if one of your devices/apps was reaching out to &lt;STRONG&gt;a.b.c.d&lt;/STRONG&gt; and your "monitor traffic" gui pane had the resolve hostname checkbox enabled - to facilitate this, the PA device&amp;nbsp; would send out a dns query for a pointer record of the domain name &lt;STRONG&gt;d.c.b.a.in-addr.arpa&lt;/STRONG&gt; to your specified dns servers. If this resolve fails ... it logs it in the system log as type: dnsproxy, severity: informational, event: resolve-fail, object: mgmt-obj and provides a description of the failed reverse lookup attempt&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 14:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/211891#M61783</guid>
      <dc:creator>craiglunt</dc:creator>
      <dc:date>2018-04-26T14:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNSproxy resolve fail msgs - only I am not using this feature!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/211909#M61792</link>
      <description>&lt;P&gt;I actually created a support ticket for this issue.&amp;nbsp; 8.1 was when I first saw the issue as well.&amp;nbsp; I have been told that this is a know bug with 8.1 and it will be addressed with 8.1.1.&amp;nbsp; 8.1.1 should be available around May 3rd.&amp;nbsp; Here is the bug id for this issue:&lt;/P&gt;&lt;P&gt;PAN-94640&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 15:53:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dnsproxy-resolve-fail-msgs-only-i-am-not-using-this-feature/m-p/211909#M61792</guid>
      <dc:creator>meyer37</dc:creator>
      <dc:date>2018-04-26T15:53:51Z</dc:date>
    </item>
  </channel>
</rss>

