<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules[SOLUTION] in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230226#M66188</link>
    <description>&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;U&gt;First I would like to say that we are pursuing this with CarbonBlack and we have worked with PAN support already to see what our options are.&amp;nbsp; This is as much an informative post as it is to see what other people think and are doing.&lt;/U&gt;&lt;BR /&gt;For the record PAN support suggested changing the DNS entry from a lookup to a FTP file check.&amp;nbsp; We would prefer to correct the actual problem rather than do this and use the three cron jobs I created (if I die/quit/etc they don't want to have to figure it out, I don't blame them).&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#ff0000" face="Calibri" size="5"&gt;On to post #2 and the topic!&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;FONT face="Calibri" size="3"&gt;There is a solution.&amp;nbsp; See below.&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Sep 2018 18:47:27 GMT</pubDate>
    <dc:creator>BrianRa</dc:creator>
    <dc:date>2018-09-11T18:47:27Z</dc:date>
    <item>
      <title>Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules[SOLUTION]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230226#M66188</link>
      <description>&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;U&gt;First I would like to say that we are pursuing this with CarbonBlack and we have worked with PAN support already to see what our options are.&amp;nbsp; This is as much an informative post as it is to see what other people think and are doing.&lt;/U&gt;&lt;BR /&gt;For the record PAN support suggested changing the DNS entry from a lookup to a FTP file check.&amp;nbsp; We would prefer to correct the actual problem rather than do this and use the three cron jobs I created (if I die/quit/etc they don't want to have to figure it out, I don't blame them).&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#ff0000" face="Calibri" size="5"&gt;On to post #2 and the topic!&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;FONT face="Calibri" size="3"&gt;There is a solution.&amp;nbsp; See below.&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 18:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230226#M66188</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-11T18:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230227#M66189</link>
      <description>&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;We are currently fighting a problem with the dev-prod05.conferdeploy.net domain name and our firewall rules.&amp;nbsp; When doing a DNS lookup on this domain devices return 8 IPs.&amp;nbsp; However this domain has at any given time 30 IP entries (based on the monitoring script I wrote that resets every 24 hours).&amp;nbsp; If you work with firewalls (or any device) you know that they only do a DNS lookup every so often then cache the results.&amp;nbsp; This is a problem when a PC/Server can do the same lookup and come up with 22 IPs the firewall does not know about.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;We are seeing the firewall allowing and rejecting the same domain name because it does not know the IPs the client is trying to reach (see the excel document).&amp;nbsp; This would be fairly simple (though clunky) to either tell the firewall to check a FTP file with the list of IPs in it for that domain or just enter all the IPs into a firewall rule and ignore the DNS but over the last couple of months monitoring dev-prod05.conferdeploy.net the IPs have changed.&amp;nbsp; This is the reason I set the script to reset every 24 hours.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;What are people doing to combat this problem?&amp;nbsp; Other sites do not present in this manner.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;Is this a security thing for CB Defense (so many IPs its hard to take down)?&amp;nbsp; Or a misconfiguration on the DNS that shows all the current IPs regardless of the region your IP is in?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;This can be tested at any time by opening the command line and typing “&lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;&lt;SPAN&gt;nslookup dev-prod05.conferdeploy.net&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT color="#000000" size="3"&gt;” (Windows) 4 or 5 times in a row.&amp;nbsp; Each time 8 IPs will present and each time there will be IPs that were not listed in the previous lookup.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;Our specs:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;Palo Alto Firewalls (8.x)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;Windows 7/10 desktops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;Windows 2012/2016 servers&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;Linux scripts:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;RUN EVERY 5 MINUTES&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;FONT color="#0000ff"&gt;host dev-prod05.conferdeploy.net | grep has | awk '{print $4}' &amp;gt;&amp;gt; dev-prod05.conferdeploy.net_BULK-IPs.txt&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;RUN EVERY 10 MINUTES&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;FONT color="#0000ff"&gt;awk '!seen[$0]++' dev-prod05.conferdeploy.net_BULK-IPs.txt &amp;gt; dev-prod05.conferdeploy.net.txt&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;RUN ONCE A DAY:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;FONT color="#0000ff"&gt;rm /dev-prod05.conferdeploy.net_BULK-IPs.txt&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 18:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230227#M66189</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-10T18:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230235#M66190</link>
      <description>&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Generate Time&lt;/TD&gt;&lt;TD&gt;Source&lt;/TD&gt;&lt;TD&gt;Destination&lt;/TD&gt;&lt;TD&gt;Destination address&lt;/TD&gt;&lt;TD&gt;Application&lt;/TD&gt;&lt;TD&gt;Action&lt;/TD&gt;&lt;TD&gt;URL&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 10:00&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.214.112.236&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 10:00&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.54.80&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 10:00&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 10:00&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 10:00&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.44.112&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:59&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.88.190&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:59&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.88.190&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:59&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.227.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.237.240.4&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.237.240.4&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.237.240.4&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.237.240.4&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.237.240.4&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;35.173.197.210&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;35.173.197.210&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.206.73.176&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.206.73.176&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.206.73.176&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.234.104.211&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:56&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.54.80&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.44.112&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.166.1&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.88.190&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.213.132.157&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.213.132.157&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.210.120&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:55&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:54&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.213.132.157&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:54&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;52.207.81.137&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:54&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;52.207.81.137&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:54&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.227.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.54.80&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.44.112&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.44.112&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.227.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.166.1&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.166.1&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.210.120&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.227.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:53&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.44.112&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.166.1&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.166.1&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:52&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.44.112&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:51&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:51&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:51&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.227.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:51&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.244.92&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:51&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;52.207.81.137&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:50&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;52.207.81.137&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:50&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;52.207.81.137&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.227.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.210.120&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.210.120&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.54.80&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.198.54.80&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.192.210.120&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.213.132.157&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.213.132.157&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.213.132.157&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.197.159.199&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:49&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.199.106.239&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.191.180&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.238.4.33&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;35.173.197.210&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.238.4.33&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;35.173.197.210&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.238.4.33&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.206.73.176&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.206.73.176&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.206.73.176&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.214.112.236&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.214.112.236&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.194.191.180&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.238.4.33&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:48&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.225.200.240&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:47&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.237.240.4&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;alert&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:47&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;18.214.112.236&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/10/2018 9:47&lt;/TD&gt;&lt;TD&gt;Internal&lt;/TD&gt;&lt;TD&gt;External&lt;/TD&gt;&lt;TD&gt;34.239.202.48&lt;/TD&gt;&lt;TD&gt;ssl&lt;/TD&gt;&lt;TD&gt;block-url&lt;/TD&gt;&lt;TD&gt;dev-prod05.conferdeploy.net&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 10 Sep 2018 18:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230235#M66190</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-10T18:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230243#M66191</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I know your post was more informational than anything else, but ...&lt;/P&gt;&lt;P&gt;... just a though but as these connections are all "ssl", why don't you allow this traffic with a custom URL category that you specify directly in your security policy rule instead of using an FQDN object?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 20:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230243#M66191</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-10T20:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230449#M66221</link>
      <description>&lt;P&gt;I'm not great with Linux so&amp;nbsp;I want to verify my understanding of what your scripts are doing.&lt;/P&gt;&lt;P&gt;The script that runs every 5 minutes seems to run a lookup on that particular host and output the results to a text file.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Is that text file appended or overwritten?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The script that runs every 10 minutes looks for duplicates and outputs the results to a text file.&amp;nbsp;Is that text file appended or overwritten?&lt;/P&gt;&lt;P&gt;The PA does a FQDN refresh every 30 minutes and I think it can only reference 10 results per FQDN so that won't work with the frequency or quantity that you need.&lt;/P&gt;&lt;P&gt;If the second script is appending so that you have a list of permitted IP addresses in that text file, then you can reference that file with an external dynamic list and build that into a security policy. We use many EDLs, including one that we publish internally for blocking certain sites. Our internal list only changes a few times a week so it's not all that dynamic. But its not clunky and works fine with minimal maintenance.&lt;/P&gt;&lt;P&gt;Not a great solution but......you could push out a host file to all the endpoints with a bunch of the correct IP addresses and resolve them to&amp;nbsp;&lt;SPAN&gt;dev-prod05.conferdeploy.net. That would control specifically which IPs the endpoints will try to access and not rely on DNS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 15:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230449#M66221</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2018-09-11T15:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230450#M66222</link>
      <description>&lt;P&gt;&lt;STRONG&gt;vsys_remo&lt;/STRONG&gt; thanks for the reply.&lt;/P&gt;&lt;P&gt;We currentlly have a rule for all "non internet" users/machines that has a URL Filter and we have added a "vendor whitelist" URL Category.&amp;nbsp; The domain is in this custom list.&amp;nbsp; This rule also onlly allows SSL and HTTP applications.&lt;/P&gt;&lt;P&gt;This is the rule that is sometimes allowing access and other times denying based on whether or not the PA knows about the IP being used.&amp;nbsp; I may be missing something you are adding but the custom URL Category list only allows me to put in domains.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 16:07:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230450#M66222</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-11T16:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230451#M66223</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;This is the rule that is sometimes allowing access and other times denying based on whether or not the PA knows about the IP being used.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Then - as far as I know PaloAlto - there must be something else that prevents the access, because when you allow access based on a URL the firewall does not care about the IP behind the domainname/URL. In this case the firewall only checks the http host header or SNI extension / certificate CN in a TLS connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The logs that you posted: Are these logs all from the same security policy rule? Do you may be specify sourceaddresses in that rule that does not allow the access for all servers that need to connect to that URL? I am asking this because there are multiple IP addresses that are both allowed and blocked and so far I am not (and never was) aware of a bug that results in such a behaviour. Here are some IPs that are allowed and blocked in your log:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;34.197.244.92&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;34.198.88.190&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;34.197.159.199&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 11 Sep 2018 16:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230451#M66223</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-11T16:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230460#M66227</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;I will break each one down so it makes more sense.&amp;nbsp; If you understand more than this and it is redundant I apologize but I want to make sure it is all clear.&amp;nbsp; All definitions are in reference to what I am doing with it.&amp;nbsp; A not on the ".txt" extension, this has nothing to do with linux but makes it easily Windows readable (auto opens in notepad++ for me).&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;host &lt;/FONT&gt;= nslookup&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;|&lt;/FONT&gt; breaks out for the new command based on the results of the previous command&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;grep&lt;/FONT&gt; = search request based on the result of "host" command (because of the pipe) containing the word "has"&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;awk&lt;/FONT&gt; = a programing language initiator for printing the 4th value in the string based on a space breakout&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;&amp;gt;&amp;gt;&lt;/FONT&gt; is equl to an append at the end of file&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;&amp;gt;&lt;/FONT&gt; is equal to a replace/create file&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&lt;FONT color="#ff6600"&gt;rm&lt;/FONT&gt; = remove file&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;RUN EVERY 5 MINUTES &lt;FONT color="#ff0000"&gt;(Done every 5 minutes to try to capture all the IPs that are available)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;FONT color="#0000ff"&gt;host dev-prod05.conferdeploy.net | grep has | awk '{print $4}' &amp;gt;&amp;gt; dev-prod05.conferdeploy.net_BULK-IPs.txt&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;dev-prod05.conferdeploy.net has address 52.45.174.75&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;dev-prod05.conferdeploy.net has address 52.2.229.136&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;Find all lines that contain "has" in the line&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;Now pull out the 4th variable based on a space delimiter from each line&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;&lt;FONT face="Calibri"&gt;52.45.174.75&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;&lt;FONT face="Calibri"&gt;&lt;FONT color="#ff0000" face="Calibri"&gt;52.2.229.136&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000" face="Calibri" size="3"&gt;&lt;FONT face="Calibri"&gt;Paste that value at the end of the current/defined txt file&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;RUN EVERY 10 MINUTES &lt;FONT color="#ff0000"&gt;(Done every 10 minutes to try to capture new IPs but there is no reason to do it as often because the likely hood of a new IP after the first hour is low)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;FONT color="#0000ff"&gt;awk '!seen[$0]++' dev-prod05.conferdeploy.net_BULK-IPs.txt &amp;gt; dev-prod05.conferdeploy.net.txt&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;Search in the defined "BULK-IPs.txt" file for a unique value&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;Repeat this command for all lines in this file&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;Paste that unique values into a new/overwritten defined txt file&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Calibri" size="3"&gt;RUN ONCE A DAY: &lt;FONT color="#ff0000"&gt;(I chose once daily because it is easy to troubleshoot and keeps the file down to the expected 30 IPs)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;FONT color="#0000ff"&gt;rm /dev-prod05.conferdeploy.net_BULK-IPs.txt&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;Remove the defined "BULK-IPs.txt" file&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;There is no reason to rm/delete the &lt;FONT face="Calibri"&gt;dev-prod05.conferdeploy.net.txt final product file because it is already overwritten every 10 minutes with a new file&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&lt;FONT face="Calibri"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="Calibri" size="3"&gt;&lt;FONT face="Calibri"&gt;Please let me know if any of this does not make sense and I will try to explain it.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 18:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230460#M66227</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-11T18:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230471#M66229</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;I have included the rule.&amp;nbsp; We have tried with both Application and Service (better results for internet access in general with Services as it turns out).&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="temp.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16591i63D2CD3DE08B5DFF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="temp.jpg" alt="temp.jpg" /&gt;&lt;/span&gt;Yes all the log results are the results of that rule.&amp;nbsp; We removed all confidential/internal data from the excel sheet.&amp;nbsp; In that timeframe dozens of hosts had made requests to get to the site.&amp;nbsp; All the "Destination address" results are valid IPs for the dev-prod05.conferdeploy.net domain.&amp;nbsp; &lt;STRIKE&gt;From what I understand the firewall checks the DNS of the requested domain/site and if they do not match blocks the request (DNS poisoning of a client can be prevented this way).&lt;/STRIKE&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;[EDIT]&lt;/EM&gt;&lt;/U&gt;&lt;STRIKE&gt;&lt;BR /&gt;&lt;/STRIKE&gt;I stand corrected.&amp;nbsp; We did not have that domain properly in the "Vendors Whitelist" like we should have.&amp;nbsp; We had a ruler higher up in the stack we were using that IS using FQDN for all CarbonBlack domains we need.&amp;nbsp; I added the dev-prod05.conferdeploy.net properly (spelling) into the custom URL Category and it is functioning properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FQDN - does a DNS lookup to ensure the information is correct&lt;/P&gt;&lt;P&gt;Custom Objects -&amp;gt; URL Category - only checks the domain to ensure it is in the allowed/denied list (as this is SSL an invalid cert warning should popup [in a browser] or the application should [hopefully] fail due to the failed cert)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;U&gt;[/EDIT]&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 18:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230471#M66229</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-11T18:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230499#M66234</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Custom Objects -&amp;gt; URL Category - only checks the domain to ensure it is in the allowed/denied list (as this is SSL an invalid cert warning should popup [in a browser] or the application should [hopefully] fail due to the failed cert)&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The cert is only changed by the firewall if you have TLS decryption enabled. Otherwise the connection is simply allowed/denied based on the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About the previous confusion with the DNS lookups. Maybe you mixed something with the HTTP and TLS evasion Anti-Spyware feature. Because you are right allowing only the access based on a URL actually opens a secuirty risk. So if you really need high security while still allowing specific access to the internet (really high security and internet are mutually exclusive - but thats just my opinion &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&amp;nbsp; &amp;nbsp;) you should also add IP addresses to the destination address column and if you do it the way you did with the dns lookups scripts you also need to make sure that your network is secured for DNS poisoning attacks from the internet. Anyway I wrote already too much details for something that isn't relevant here where I just wanted to explain the risk with the access based on the URL category - so back to that. The risk here is that a client only uses the name "&lt;SPAN&gt;dev-prod05.conferdeploy.net" in the TLS handshake but does not connect to an IP that effectively behind this FQDN. So if the client uses this name but connects to an IP that is controlled by an attacked, the firewall will happily allow the connection with the rule in your screenshot. And this risk can be mitigated by the use of the HTTP and TLS Evasion anti spyware signatures. But for these signatures to work properly you need to activate the DNS proxy feature that ALL dns requests pass the firewall. This way the firewall is able to detect at least situations where the client does a dns request for an fqdn but then connects to another IP than it has received in the dns reply. If a malware connects to this domain using an IP that it has received in another way than dns or a hardcoded one then the evasion signatures will not help either...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At least your problem with the access to this fqdn is solved &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 20:35:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230499#M66234</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-11T20:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Large Varying IP Pools for DNS (CB Defense dev-prod05.conferdeploy.net) And Firewall Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230513#M66239</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;wrote:&amp;nbsp;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;So if the client uses this name but connects to an IP that is controlled by an attacked, the firewall will happily allow the connection with the rule in your screenshot. &lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;As soon as I realized how that worked this was my first thought!&lt;/P&gt;&lt;P&gt;Fortunately our DNS is fairly secure (externally anyway).&amp;nbsp; However if a bad actor got in and started spoofing DNS internally then yes we would have problems.&amp;nbsp; Also a user that understands the vulnerability would be able to access sites that are blocked.&amp;nbsp; We do have all of the Security Profiles built and are using all but Data Filtering on this rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I don't know that DNS proxy would work internally as we are using split DNS internally for both domain and some site requests.&amp;nbsp; During our initial configuration Palo Alto implied this was not prefered due to the load it put on the firewall (this may not be correct but it has caused us to avoid it on most of our networks).&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="1"&gt;&lt;EM&gt;“Do not own a computer;&lt;BR /&gt;Do not power it on;&lt;BR /&gt;and do not use one.”&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="1"&gt;&lt;EM&gt;Morris’s Three Golden Rules of Computer&amp;nbsp;Security&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 23:43:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/large-varying-ip-pools-for-dns-cb-defense-dev-prod05/m-p/230513#M66239</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-09-11T23:43:01Z</dc:date>
    </item>
  </channel>
</rss>

