<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS proxy and strange system logs entries in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9002#M6577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using dns proxy from two weeks. Today I observed strange entries in logs:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-11_182036.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9057_2013-10-11_182036.png" style="width: 620px; height: 397px;" /&gt;&lt;/P&gt;&lt;P&gt;my configurqation is simple:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-11_182123.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9058_2013-10-11_182123.png" style="width: 620px; height: 344px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone help me to undestrand what is going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Oct 2013 16:25:49 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2013-10-11T16:25:49Z</dc:date>
    <item>
      <title>DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9002#M6577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using dns proxy from two weeks. Today I observed strange entries in logs:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-11_182036.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9057_2013-10-11_182036.png" style="width: 620px; height: 397px;" /&gt;&lt;/P&gt;&lt;P&gt;my configurqation is simple:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-11_182123.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9058_2013-10-11_182123.png" style="width: 620px; height: 344px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone help me to undestrand what is going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 16:25:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9002#M6577</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-11T16:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9003#M6578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These errors indicate connectivity issues to the configured DNS servers.&amp;nbsp; Has there been any events which may have caused a loss of connectivity between the firewall and those IPs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 16:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9003#M6578</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2013-10-11T16:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9004#M6579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, those two DNS servers was "pingable" all the time.&lt;/P&gt;&lt;P&gt;Also "DIG google.com" gives me answer - lunched from computer from one of network with dns_proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea how to troubleshoot it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 19:05:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9004#M6579</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-11T19:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9005#M6580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Start with enabling debug for dnsproxyd and checking dnsproxy logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; debug dnsproxyd global on debug ===&amp;gt;ENABLE&amp;nbsp; debug&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log dnsproxyd.log ===== CHECK logs&lt;/P&gt;&lt;P&gt;&amp;gt; debug dnsproxyd global on info ===&amp;gt;DISABLE&amp;nbsp; debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Possible Issues:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt; Server Sending DNS Response larger than 512 bytes&lt;/P&gt;&lt;P&gt;Extended DNS (&amp;gt;512B) option not supported with PA as proxy.&lt;/P&gt;&lt;P&gt;FIX: &lt;A href="http://support.microsoft.com/kb/832223" title="http://support.microsoft.com/kb/832223"&gt;Some DNS name queries are unsuccessful after you deploy a Windows Server 2003 or Windows Server 2008 R2-based DNS server&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2&amp;gt; DNSproxy logs show " No buffer space available."&lt;/P&gt;&lt;P&gt;Fixed with OS-5.0.8&lt;/P&gt;&lt;P&gt;Bug 50813—DNS proxy fails to proxy traffic with bursts of DNS requests, displaying the&lt;/P&gt;&lt;P&gt;error: (errno: 105) No buffer space available. This was resolved by&lt;/P&gt;&lt;P&gt;increasing the buffer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;3&amp;gt; Sessions for sourced from dnsproxy interface to the server being scanned spyware profile being discarded.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Configure a security rule to bypass threat scanning for the traffic to the DNS server sourced&amp;nbsp; from DNSproxy interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;You can enable threat scanning for traffic from the original clients to DNS proxy and also DNS response traffic (public DNS servers)&amp;nbsp; if needed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 22:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9005#M6580</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-10-13T22:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9006#M6581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You for very detailed answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that the best option for me will be upgrade to 5.0.8 and after check logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had this errors ie 10.10.2013 about 13:58, in dnsproxyd.log a have enries:&lt;/P&gt;&lt;P&gt;Oct 10 14:52:58 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Oct 10 14:54:57 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1335): [14122/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:14122&lt;/P&gt;&lt;P&gt;Oct 10 14:54:57 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[14122] entry is already freed!&lt;/P&gt;&lt;P&gt;Oct 10 14:54:57 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Oct 10 14:55:37 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1335): [44552/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:44552&lt;/P&gt;&lt;P&gt;Oct 10 14:55:37 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[44552] entry is already freed!&lt;/P&gt;&lt;P&gt;Oct 10 14:55:37 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Oct 10 15:06:14 Error: cfgagent_modify_callback(pan_cfgagent.c:81): Modify string (sw.mgmt.runtime.clients.dnsproxyd.err) error: Unknown error code (1)&lt;/P&gt;&lt;P&gt;Oct 10 15:10:36 Error: pan_dnsproxy_query_done_cb(pan_dnsproxy_pkt.c:772): Cache entry not found for Wsadecka.feris.pl.&lt;/P&gt;&lt;P&gt;Oct 10 15:52:34 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1335): [26579/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:26579&lt;/P&gt;&lt;P&gt;Oct 10 15:52:34 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[26579] entry is already freed!&lt;/P&gt;&lt;P&gt;Oct 10 15:52:34 Error: pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): [Drop Rcvd Server Pkt]: Error in processing packet&lt;/P&gt;&lt;P&gt;Oct 10 15:53:00 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1335): [36977/-][Drop Rcvd Server Pkt]: No pending entry in conn tbl for server_tid:36977&lt;/P&gt;&lt;P&gt;Oct 10 15:53:00 Error: remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284): conn_tbl[36977] entry is already freed!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is everything OK in this logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to make rule for &amp;gt;3&lt;/P&gt;&lt;P&gt;In my scenario I have DNS servers in Zone A, clients in Zone B, my security rule:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-10-14_162722.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9079_2013-10-14_162722.png" style="width: 620px; height: 36px;" /&gt;&lt;/P&gt;&lt;P&gt;Should I add rule that alloving traffic from WiFi zone (with source IP = gateway IP for this zone) to Zone A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN style="font-size: 10pt;"&gt;You can enable threat scanning for traffic from the original clients to DNS proxy and also DNS response traffic (public DNS servers)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;How to achieve that?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Should I make rule from WiFi to WiFi app=dns with enabled thread prevention profile on it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 14:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9006#M6581</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-14T14:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9007#M6582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;This seems to be an issue related to configuration of Threat scanning as logs do not indicate any Buffer related messages.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;You should be able to confirm this by checking the session table for destination = DNS server in DISCARD state during the failure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-size: 10pt; font-style: inherit; text-decoration: underline; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;Assuming :&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Clients and DNSproxy Interface===&amp;gt;ZONE &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;WiFi&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-style: inherit; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;DNS servers - Zone B&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;You an create a security policy as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-family: inherit; font-size: 10pt; font-style: inherit; line-height: 1.5em;"&gt;Zone WiFi to Zone WiFi app=dns with enabled thread prevention profile .&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-family: inherit; font-size: 10pt; font-style: inherit; line-height: 1.5em;"&gt;Zone &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;WiFi to Zone B &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;app=dns Destination IP : DNS servers ==&amp;gt; Should not have threat profiles.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-family: inherit; font-size: 10pt; font-style: inherit; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-family: inherit; font-size: 10pt; font-style: inherit; line-height: 1.5em;"&gt;HTH,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-family: inherit; font-size: 10pt; font-style: inherit; line-height: 1.5em;"&gt;Ameya&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 20:55:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9007#M6582</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-10-14T20:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy and strange system logs entries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9008#M6583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From 10.10.2013 I had no problem with dns proxy so I can't do any further investigations. I'm waiting for another issue with dns proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Oct 2013 07:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-and-strange-system-logs-entries/m-p/9008#M6583</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-10-16T07:45:24Z</dc:date>
    </item>
  </channel>
</rss>

