<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS &amp;quot;Aged Out&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241001#M69042</link>
    <description>&lt;P&gt;More information...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will get all of the details of my configuration here in a bit but for now, this is the update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chronology:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Before new line was installed, connectivity was fine.&lt;/P&gt;&lt;P&gt;2) Because of a building addition, the fiber line had to be extended and they ended up giving us a new wan ip for the extended line.&amp;nbsp; We were not informed of this until later.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) The ip schema was faulty and many LIVE folks contributed.&amp;nbsp; Thanks.&amp;nbsp; That is correct now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN GW:&amp;nbsp; 80.80.169.1&lt;/P&gt;&lt;P&gt;WAN&amp;nbsp; IP:&amp;nbsp; 80.80.169.16/25&lt;/P&gt;&lt;P&gt;PDNS: 80.80.160.8&lt;/P&gt;&lt;P&gt;SDNS: 80.80.160.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) Before the new line was installed,&amp;nbsp; we had just an ISP hardware fiber box with a fiber to ethernet converter.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) Now we have an ISP Bridge, a Huawei HG8242H, sitting between our PA 220 and the fiber connection.&lt;/P&gt;&lt;P&gt;6) I am not able to view the configuration of the bridge...they won't let me in.&lt;/P&gt;&lt;P&gt;7) For about 2 weeks we had a connection with the new line and new definitions.&amp;nbsp; However, we would have to call many mornings and have the line reset.&amp;nbsp; Then we would be good for the day.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; About a week ago last Wednesday, we could not get out to the internet at all except for a few odd little windows where we can get into a website for 2 min or less and then we are kicked out.&amp;nbsp; &amp;nbsp;Those are very rare now...today I got glimpses of just 10-20 sec.&amp;nbsp; But I went home on a Tuesday night with connectivity and came in on a Wednesday and we have been down since.&lt;/P&gt;&lt;P&gt;9) I have been suspicious of duplicate addressing of our WAN port.&amp;nbsp; I disconnected the cable going into ethernet1/1 (address of 80.80.169.16)&amp;nbsp; the other day, and from an outside&amp;nbsp; network&amp;nbsp; (hooked my computer up to my mobile phone hotspot) was still able to ping that address.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;10)&amp;nbsp; The ISP folks were here to day and they are going to check into this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will take screenshots of my configuration.&amp;nbsp; If you can find any mistake on my part, I would be so grateful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running the school now by connecting the LAN directly into another ISP's router and bypassing the PA 220.&amp;nbsp; Not happy about this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-- Joan&lt;/P&gt;</description>
    <pubDate>Fri, 23 Nov 2018 14:04:23 GMT</pubDate>
    <dc:creator>j.anderson</dc:creator>
    <dc:date>2018-11-23T14:04:23Z</dc:date>
    <item>
      <title>DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239596#M68628</link>
      <description>&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;ISP changed fiber line coming into site.&amp;nbsp; DNS server addresses did not change (they say) but the external addresses and gateway did change.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;I can connect to the internet but just for about 2 to 3 minutes and then I lose access to the internet.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;Updated all definitions with the new information.&amp;nbsp; Simple network…&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;LAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;192.168.1.1/24&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;192.168.1.1 GW&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;WAN&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;80.80.169.1 WAN GW&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;80.80.169.16/30&amp;nbsp; WAN Range&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;P DNS 80.80.160.8&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;S DNS 80.80.160.9&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;Static Route points to 80.80.169.1 and defined on the ethernet1/1 interface.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;Can I safely assume that the configuration is correct?&amp;nbsp; And that there is a timeout issue?&amp;nbsp; I changed default / global timeout values for tcp and udp.&amp;nbsp; Then I could not connect at all.&amp;nbsp; Reverted.&amp;nbsp; Changed timeouts for DNS.&amp;nbsp; Same.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;Thanks for your help.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="Calibri,sans-serif" size="2"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Nov 2018 00:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239596#M68628</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-13T00:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239605#M68631</link>
      <description>&lt;DIV&gt;&lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;WAN&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;80.80.169.1 WAN GW&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;80.80.169.16/30&amp;nbsp; WAN Range&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;P DNS 80.80.160.8&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;S DNS 80.80.160.9&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are they sure this is correct?&amp;nbsp; I would expect your gateway to be &lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;80.80.169.17 and the PAN interface&amp;nbsp;80.80.169.18&lt;/SPAN&gt;&lt;/FONT&gt; since the interface subnet is a &lt;FONT size="2" face="Calibri,sans-serif"&gt;&lt;SPAN&gt;80.80.169.16/30&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 01:24:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239605#M68631</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-11-13T01:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239606#M68632</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; I won't be able to speak with them until the morning.&amp;nbsp; It is 2:30 a.m. my time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try your suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 01:29:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239606#M68632</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-13T01:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239607#M68633</link>
      <description>&lt;P&gt;No luck.&amp;nbsp; &amp;nbsp;Can't find primary DNS.&amp;nbsp; Set x.x.169.17 as gateway and the interface as x.x.x.18/30&amp;nbsp; (correct?).&amp;nbsp; Next hop was set to x.x.169.17.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another router here from another ISP.&amp;nbsp; When I get out through that router and ping the other ISP's addresses, I find that I can ping the 80.80.169.1 gateway but not x.x.x.16 and beyond.&amp;nbsp; I cannot also ping the PDNS and SDNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything else I can do before I speak with them again?&amp;nbsp; I would like to rule out the firewall if I can.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They claim that since they are providing connectivity to the port (lights flash), that the problem is with the firewall config.&amp;nbsp; Since they changed the line and gave it a&amp;nbsp; new ip, we could connect and use it up until today.&amp;nbsp; But even still...every morning it needed to be reset by them.&amp;nbsp; Today they mapped x.x.169.1 to the FW mac address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 02:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239607#M68633</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-13T02:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239609#M68634</link>
      <description>&lt;P&gt;I just set everything back to as it was in my first email.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got in right away to our network.&amp;nbsp; I have about 30 sec to 1 min before dns ages out.&amp;nbsp; I was able to ping the x.x.169.1 gateway and both DNS servers.&amp;nbsp; I could not ping x.x.x.16, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you know what is causing dns to age out?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 02:38:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239609#M68634</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-13T02:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239612#M68636</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&amp;nbsp;mentioned&amp;nbsp;&lt;SPAN&gt;80.80.169.16/30 means that you can use only IPs&amp;nbsp;80.80.169.17 and&amp;nbsp;80.80.169.18.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One of them has to be your public IP and other ISP gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can't use&amp;nbsp;80.80.169.16/30 as interface IP as this is not usable IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Try both ways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;First assign&amp;nbsp;80.80.169.18/30 to your firewall and then try to ping ISP gw.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; ping source&amp;nbsp;80.80.169.18 host&amp;nbsp;80.80.169.17&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And then check arp table&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show arp ethernet1/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(a&lt;/SPAN&gt;&lt;SPAN&gt;ssuming that your wan interface is on ethernet1/1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you see mac address behind&amp;nbsp;80.80.169.17?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you see incomplete then try&amp;nbsp;80.80.169.17/30 on fw interface and ping 18.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If mac is there then can you ping 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; ping source&amp;nbsp;80.80.169.18 host 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If not then check if your routing is correct&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;traceroute source&amp;nbsp;80.80.169.18 host 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is next hop&amp;nbsp;80.80.169.17?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 03:23:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239612#M68636</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-13T03:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239899#M68725</link>
      <description>&lt;P&gt;Thank you to&amp;nbsp;@Raido and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a volunteer math teacher overseas and have inherited the networking role.&amp;nbsp; I have a distant background in the basics so bear with me as I get up to speed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was finally able to show the ISP guys the addressing fault issue.&amp;nbsp; Now I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN IP:&amp;nbsp; 80.80.169.16/25&amp;nbsp; (x.x.x.16 is mapped ... on the ISP side...to the PA 220 mac address)&amp;nbsp;&lt;/P&gt;&lt;P&gt;GW:&amp;nbsp; 80.80.169.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PDNS:&amp;nbsp; 80.80.160.8&lt;/P&gt;&lt;P&gt;SDN:&amp;nbsp; 80.80.160.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Static Route:&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Default:&amp;nbsp; 0.0.0.0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Next Hop:&amp;nbsp; 80.80.169.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT Policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Original Packet&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Source Zone:&amp;nbsp; trust&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Destintaion Zone:&amp;nbsp; untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Destination Interface: any&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Source and Destination address:&amp;nbsp; any&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Translated Packet&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Translation Type:&amp;nbsp; Dynamic IP and Port&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Address Type:&amp;nbsp; Interface Address&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Interface:&amp;nbsp; ethernet1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP address:&amp;nbsp; 80.80.169.16/25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ethernet1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Zone:&amp;nbsp; untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP:&amp;nbsp; 80.80.169.16/25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ethernet1/3&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Zone:&amp;nbsp; trust&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP: 192.168.1.1/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP Server&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ethernet1/3&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Pool:&amp;nbsp; 192.168.1.1/24&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;GW: 192.168.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Subnet Mask:&amp;nbsp; 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PDNS:&amp;nbsp; 80.80.160.8&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SDNS:&amp;nbsp; 80.80.160.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still cannot connect to the internet.&amp;nbsp; I can do the following though...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;flushdns, release ip, connect to the internet via PA220 .&amp;nbsp; When I get in, I have about 2 minutes before I get kicked out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During that time, I can tracert to both 8.8.8.8 and google.com, etc.&amp;nbsp; I can ping the interface, the dns servers and the wan gw.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From CLI I can look at any/all session id's.&amp;nbsp; They all end with a reason of n/a or aged out.&amp;nbsp; Some are at INIT state, others ACTIVE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I could not get in at all and saw that the protocal in the session id was almost always udp (dns appl.), I uncreased that timer to 120 sec.&amp;nbsp; That seems to allow me to play this game.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 19:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239899#M68725</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-14T19:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239900#M68726</link>
      <description>&lt;P&gt;My PA-220 software version is 8.0.3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an update in the 8.0.7 version that fixes a DNS failure issue due to BFD packets being associated with the destination port and not DNS packets.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checking into this...thanks for any input.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 20:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239900#M68726</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-14T20:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239926#M68729</link>
      <description>&lt;P&gt;What you have there now looks good.&amp;nbsp; I assume there is also a security policy from trust to untrust allowing the internet access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a computer you can plug into the service port instead of the PAN and manually configure this information on the NIC.&lt;/P&gt;&lt;P&gt;WAN IP:&amp;nbsp; 80.80.169.16/25&amp;nbsp; (x.x.x.16 is mapped ... on the ISP side...to the PA 220 mac address)&amp;nbsp;&lt;/P&gt;&lt;P&gt;GW:&amp;nbsp; 80.80.169.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PDNS:&amp;nbsp; 80.80.160.8&lt;/P&gt;&lt;P&gt;SDN:&amp;nbsp; 80.80.160.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then test with your ISP.&amp;nbsp; This removes the firewall from the path and the computer connected on this WAN address should have full internet access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mention the ISP is doing mac address locks.&amp;nbsp; So to do this test they would have to release that and allow the address to be used by the computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will confirm whether the issue is some configuration on the PAN or the service itself not allowing full access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 01:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/239926#M68729</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-11-15T01:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/240050#M68760</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95536"&gt;@j.anderson&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;flushdns, release ip, connect to the internet via PA220 .&amp;nbsp; When I get in, I have about 2 minutes before I get kicked out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During that time, I can tracert to both 8.8.8.8 and google.com, etc.&amp;nbsp; I can ping the interface, the dns servers and the wan gw.&lt;/P&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;If you can reach google DNS (8.8.8.8) and you suspect faulty ISP DNS. Why don't you try to put 8.8.8.8 as DNS for the PC behind the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For DNS you will always see the session ending reason - Aged out. that is because DNS is UDP and as such there is no way firewall knows when connection is ended or not. If it is TCP connection you have FIN or RST flags to mark the ending of a connection, firewall can see that and note in the logs that connection has ended normaly (with FIN) or is being reset by the client or server. UDP on other hand doesn't provide such functionality, so FW cannot tell if there are no other packets after the DNS reply. Thay is why FW is waiting for the DNS timeout timer to expire to remove the connection from the connection table. A healthy DNS connection will still be closed as aged-out, even if the reply was received right after the request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For that reason the UDP timeout timer is relevantly slow number, if it is higher you can end up with lots of old connection filling the firewall table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my huble opinion there are quite a lot other scenarios that I don't see how increasing the UDP timeout can solve your issue. If you increase it to 120sec and you see improvment, that is not problem of the firewall, but you have HUUGE delay and even if you solve the dns you will have unusable slow connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point is quite clear for me that your ISP has some issues...If you are able to traceroute and ping 8.8.8.8 while you don't have internet connection, this clearly shows that you indeed have internet connectivity, but either the DNS you are using is having issues, or there is huge delay of the traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 20:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/240050#M68760</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2018-11-15T20:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/240699#M68940</link>
      <description>&lt;P&gt;Thanks again to all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working in a country in Europe that is still quite underdeveloped and it has been difficult to work closely with the ISPs.&lt;/P&gt;&lt;P&gt;We have another ISP now working with us as the first one seems to share WAN addressing with its customers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am hoping that on Friday they will come onsite and we will hash this out until it works.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we are their only customer with a firewall in between their network and our LAN.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for staying with me and for all of the advice.&amp;nbsp; &amp;nbsp;I may put more of my configuration out in the next day or so just to make sure that there are no errors on my end.&amp;nbsp; I am so grateful to you for your time and advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best...&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 07:57:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/240699#M68940</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-21T07:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241001#M69042</link>
      <description>&lt;P&gt;More information...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will get all of the details of my configuration here in a bit but for now, this is the update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chronology:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Before new line was installed, connectivity was fine.&lt;/P&gt;&lt;P&gt;2) Because of a building addition, the fiber line had to be extended and they ended up giving us a new wan ip for the extended line.&amp;nbsp; We were not informed of this until later.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) The ip schema was faulty and many LIVE folks contributed.&amp;nbsp; Thanks.&amp;nbsp; That is correct now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WAN GW:&amp;nbsp; 80.80.169.1&lt;/P&gt;&lt;P&gt;WAN&amp;nbsp; IP:&amp;nbsp; 80.80.169.16/25&lt;/P&gt;&lt;P&gt;PDNS: 80.80.160.8&lt;/P&gt;&lt;P&gt;SDNS: 80.80.160.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) Before the new line was installed,&amp;nbsp; we had just an ISP hardware fiber box with a fiber to ethernet converter.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) Now we have an ISP Bridge, a Huawei HG8242H, sitting between our PA 220 and the fiber connection.&lt;/P&gt;&lt;P&gt;6) I am not able to view the configuration of the bridge...they won't let me in.&lt;/P&gt;&lt;P&gt;7) For about 2 weeks we had a connection with the new line and new definitions.&amp;nbsp; However, we would have to call many mornings and have the line reset.&amp;nbsp; Then we would be good for the day.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; About a week ago last Wednesday, we could not get out to the internet at all except for a few odd little windows where we can get into a website for 2 min or less and then we are kicked out.&amp;nbsp; &amp;nbsp;Those are very rare now...today I got glimpses of just 10-20 sec.&amp;nbsp; But I went home on a Tuesday night with connectivity and came in on a Wednesday and we have been down since.&lt;/P&gt;&lt;P&gt;9) I have been suspicious of duplicate addressing of our WAN port.&amp;nbsp; I disconnected the cable going into ethernet1/1 (address of 80.80.169.16)&amp;nbsp; the other day, and from an outside&amp;nbsp; network&amp;nbsp; (hooked my computer up to my mobile phone hotspot) was still able to ping that address.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;10)&amp;nbsp; The ISP folks were here to day and they are going to check into this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will take screenshots of my configuration.&amp;nbsp; If you can find any mistake on my part, I would be so grateful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running the school now by connecting the LAN directly into another ISP's router and bypassing the PA 220.&amp;nbsp; Not happy about this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-- Joan&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 14:04:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241001#M69042</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-23T14:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: DNS "Aged Out"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241007#M69048</link>
      <description>&lt;P&gt;From the CLI, I can ping the WAN IP but not the WAN GW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 16:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241007#M69048</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-23T16:17:22Z</dc:date>
    </item>
    <item>
      <title>(Re: DNS "Aged Out")  //  Updated:  No connection to internet after ISP changes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241057#M69055</link>
      <description>&lt;P&gt;Also:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000080"&gt;&lt;EM&gt;&lt;STRONG&gt;From the CLI on the management interface, I can ping the WAN port but not the WAN GW (next hop).&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000080"&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000080"&gt;&lt;EM&gt;&lt;STRONG&gt;Thank you.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config. pictures:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Interfaces" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17665i4EBF20ED733F2B4F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Interfaces2.jpg" alt="Interfaces" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Interfaces&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHCP Server" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17666iFDD5660A5A90F0B6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DHCP2.jpg" alt="DHCP Server" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;DHCP Server&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Static Route" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17667i0A374C9E2AA65161/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="static route.jpg" alt="Static Route" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Static Route&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Static Route Detail" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17668i2384F110153A6446/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Static route detail.jpg" alt="Static Route Detail" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Static Route Detail&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHCP Lease" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17669i1AF9935A9F59AA6F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DHCP Lease2.jpg" alt="DHCP Lease" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;DHCP Lease&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHCP Options" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17670i8136A7B00DA89FF5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DHCP Options2.jpg" alt="DHCP Options" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;DHCP Options&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17671i9C06F03BDA94D6EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT2.jpg" alt="NAT" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NAT&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17672iAF86C70DC11F1109/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns2.jpg" alt="DNS" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;DNS&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sec Policy 1" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17673iB3E3611A14D8E6B6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Security Policy2.jpg" alt="Sec Policy 1" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sec Policy 1&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sec Policy View 2" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17674iEF7F3D059A96FCFA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sec pol 32.jpg" alt="Sec Policy View 2" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sec Policy View 2&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sec Policy Actions" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17675iBFDD50D5794D0685/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sec pol 22.jpg" alt="Sec Policy Actions" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sec Policy Actions&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Service Route:  DNS, PA, URL" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17676iE8087A9C98608679/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Service Route2.jpg" alt="Service Route:  DNS, PA, URL" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Service Route:  DNS, PA, URL&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 22:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-quot-aged-out-quot/m-p/241057#M69055</guid>
      <dc:creator>j.anderson</dc:creator>
      <dc:date>2018-11-23T22:52:40Z</dc:date>
    </item>
  </channel>
</rss>

