<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic Logs - Resolve Hostname - Micrsoft Public IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241625#M69200</link>
    <description>&lt;P&gt;That would be nice right? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; you will be annoyed and frustrated with AWS, Akamai, Azure, etc.. at least the google stuff all resolves as 1e100 so we know who that is but you really do not know who is behind the AWS/Azure/etc IPs without a little extra legwork. Typically what I will do is go to my Linux VM, pull up the IP in firefox-&amp;gt;click add exception (because the cert will not match the IP)-&amp;gt;click view cert and then just look at the certname. There may be other ways so if anyone else has tips and tricks for this I am going to watch this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Nov 2018 16:38:17 GMT</pubDate>
    <dc:creator>hshawn</dc:creator>
    <dc:date>2018-11-29T16:38:17Z</dc:date>
    <item>
      <title>Traffic Logs - Resolve Hostname - Micrsoft Public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241617#M69198</link>
      <description>&lt;P&gt;Dear Commuity,&lt;/P&gt;&lt;P&gt;I am very new to Palo Alto Firewalls. I saw, that you can check the "Resolve hostname" checkbox when viewing Traffic Logs. Sadly a lot of IPs are not being resolved. I examed a few random samples and notices, the IPs mostly belong to Microsoft.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am now wondering, if there is some kind of way, that I could see this in Traffic Log directly. I dont necessarily need a hostname. I am happy if I would be able to display organization name behind the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eve Meier&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 16:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241617#M69198</guid>
      <dc:creator>tpmeier</dc:creator>
      <dc:date>2018-11-29T16:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs - Resolve Hostname - Micrsoft Public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241625#M69200</link>
      <description>&lt;P&gt;That would be nice right? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; you will be annoyed and frustrated with AWS, Akamai, Azure, etc.. at least the google stuff all resolves as 1e100 so we know who that is but you really do not know who is behind the AWS/Azure/etc IPs without a little extra legwork. Typically what I will do is go to my Linux VM, pull up the IP in firefox-&amp;gt;click add exception (because the cert will not match the IP)-&amp;gt;click view cert and then just look at the certname. There may be other ways so if anyone else has tips and tricks for this I am going to watch this thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 16:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241625#M69200</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-11-29T16:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs - Resolve Hostname - Micrsoft Public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241627#M69201</link>
      <description>&lt;P&gt;Open command prompt in Windows&lt;/P&gt;&lt;P&gt;ping &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case result was&amp;nbsp;172.217.3.68&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you ping IP and try to resolve to name&lt;/P&gt;&lt;P&gt;ping -a&amp;nbsp;172.217.3.68&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result was&amp;nbsp;mia07s54-in-f4.1e100.net&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not something that Palo can do - it depends on what entry is in Reverse DNS zone for this IP.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 16:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241627#M69201</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-29T16:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Logs - Resolve Hostname - Micrsoft Public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241628#M69202</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I understand what you mean. As mentioned hostname - even if it can be resolved - will often not be very helpfull in case of Microsoft, Google and others. Thats why I am wondering if the organisation name could be displayed:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.whois.com/whois/172.217.3.68" target="_blank"&gt;https://www.whois.com/whois/172.217.3.68&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose Palo Alto cant so I am wondering if there is any way I could "teach" Palo the Information I need.&lt;/P&gt;&lt;P&gt;For example this List of Public IP Range Microsoft uses I found:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=53602" target="_blank"&gt;https://www.microsoft.com/en-us/download/details.aspx?id=53602&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;btw thanks for all the fast replies &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eve Meier&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 16:59:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-logs-resolve-hostname-micrsoft-public-ips/m-p/241628#M69202</guid>
      <dc:creator>tpmeier</dc:creator>
      <dc:date>2018-11-29T16:59:06Z</dc:date>
    </item>
  </channel>
</rss>

