<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FQDN as source address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239269#M68515</link>
    <description>&lt;P&gt;Hi to all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problems with riles with FQDN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example i created&amp;nbsp;rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source ip - destination ip - destination port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed ip to FQDN object - &lt;SPAN&gt;pc1.domain.com.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;Palo Alto can resolve name to IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New Rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;source FGDN&amp;nbsp;- destination ip - destination port.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In first five minutes (more or less) rule works fine, but after that traffic not hitting this rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sometimes i see hit in traffic log, but most times traffic pass this rule and hit default rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FQDN record is present, but sometimes TTL is negative. FQDN refresh time is 1800 sec (default)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;request system fqdn show&lt;BR /&gt;FQDN Table : Last Request time Fri Nov 9 11:30:36 2018&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;IP Address Remaining TTL Secs Since Refreshed&lt;/P&gt;&lt;P&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 968 232&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 -305 1505&lt;BR /&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 -514 1714&lt;/P&gt;&lt;P&gt;request system fqdn show&lt;/P&gt;&lt;P&gt;Server error : A refresh is in progress. Please try again later.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 1099 101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What is wrong?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2018 11:54:19 GMT</pubDate>
    <dc:creator>aaobuhov</dc:creator>
    <dc:date>2018-11-09T11:54:19Z</dc:date>
    <item>
      <title>FQDN as source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239269#M68515</link>
      <description>&lt;P&gt;Hi to all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problems with riles with FQDN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example i created&amp;nbsp;rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source ip - destination ip - destination port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed ip to FQDN object - &lt;SPAN&gt;pc1.domain.com.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;Palo Alto can resolve name to IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New Rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;source FGDN&amp;nbsp;- destination ip - destination port.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In first five minutes (more or less) rule works fine, but after that traffic not hitting this rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sometimes i see hit in traffic log, but most times traffic pass this rule and hit default rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FQDN record is present, but sometimes TTL is negative. FQDN refresh time is 1800 sec (default)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;request system fqdn show&lt;BR /&gt;FQDN Table : Last Request time Fri Nov 9 11:30:36 2018&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;IP Address Remaining TTL Secs Since Refreshed&lt;/P&gt;&lt;P&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 968 232&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 -305 1505&lt;BR /&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 -514 1714&lt;/P&gt;&lt;P&gt;request system fqdn show&lt;/P&gt;&lt;P&gt;Server error : A refresh is in progress. Please try again later.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;pc1.domain.com (Objectname pc1.domain.com):&lt;/P&gt;&lt;P&gt;192.168.100.5 1099 101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What is wrong?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 11:54:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239269#M68515</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2018-11-09T11:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN as source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239303#M68528</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would assume that the TTL set on your local DNS server is less than the default FQDN refresh time, and that you might have to decrease this to less than your set TTL on the DNS server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 15:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239303#M68528</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-09T15:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN as source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239460#M68571</link>
      <description>&lt;P&gt;Thanks for the answer. Can you tell me how to check TTL on the DNS server so that I can compare it with PA FQDN refresh time?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 05:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239460#M68571</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2018-11-12T05:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN as source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239514#M68586</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Assuming Microsoft Servers are being used to supply DNS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Open DNS manager, click view --&amp;gt; advanced.&lt;/P&gt;&lt;P&gt;When you open a DNS record, there will be a new field for TTL which reveals the set TTL value.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 15:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239514#M68586</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-12T15:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN as source address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239649#M68653</link>
      <description>&lt;P&gt;My colleagues reported that TTL on the DNS server is 1 minute for local records.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 06:16:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-as-source-address/m-p/239649#M68653</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2018-11-13T06:16:04Z</dc:date>
    </item>
  </channel>
</rss>

