<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FQDN cache limitations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245581#M69970</link>
    <description>&lt;P&gt;I wanted to reach out tot he community and see how people are handling FQDN cache limit issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Internal DNS caches up to 8 IPs for each FQDN&lt;/P&gt;&lt;P&gt;* PAN device will cache up to 10 (source:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a security policy that allows traffic to blah.domain.com and that FQDN is in AWS and could be 20/30/100 IPs your traffic will not always hit the policy allowing the traffic you want to allow since the IP address the application happens to hit will not always be in the FQDN cache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;possible solution #1: have the vendor add more FQDNs (good luck)&lt;/P&gt;&lt;P&gt;possible solution #2: manually add a ton of IPs to the security policy (horrible idea)&lt;/P&gt;&lt;P&gt;possible solution #3: leave it alone and accept that the application will try again and eventually hit an IP that is cached&lt;/P&gt;&lt;P&gt;possible solution #4: Ask the vendor to use a load balancer (good luck)&lt;/P&gt;&lt;P&gt;possible solution #5: ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else run into this? I know there has to be a limit somewhere but I can see this being more and more of an issue as things are moved into the cloud.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 18:57:26 GMT</pubDate>
    <dc:creator>hshawn</dc:creator>
    <dc:date>2019-01-10T18:57:26Z</dc:date>
    <item>
      <title>FQDN cache limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245581#M69970</link>
      <description>&lt;P&gt;I wanted to reach out tot he community and see how people are handling FQDN cache limit issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Internal DNS caches up to 8 IPs for each FQDN&lt;/P&gt;&lt;P&gt;* PAN device will cache up to 10 (source:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHJCA0&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a security policy that allows traffic to blah.domain.com and that FQDN is in AWS and could be 20/30/100 IPs your traffic will not always hit the policy allowing the traffic you want to allow since the IP address the application happens to hit will not always be in the FQDN cache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;possible solution #1: have the vendor add more FQDNs (good luck)&lt;/P&gt;&lt;P&gt;possible solution #2: manually add a ton of IPs to the security policy (horrible idea)&lt;/P&gt;&lt;P&gt;possible solution #3: leave it alone and accept that the application will try again and eventually hit an IP that is cached&lt;/P&gt;&lt;P&gt;possible solution #4: Ask the vendor to use a load balancer (good luck)&lt;/P&gt;&lt;P&gt;possible solution #5: ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else run into this? I know there has to be a limit somewhere but I can see this being more and more of an issue as things are moved into the cloud.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 18:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245581#M69970</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2019-01-10T18:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN cache limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245595#M69976</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42784"&gt;@hshawn&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Solution #6: Script it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Through the API you could use a script to gather the 100 IPs a domain could be tied to, and then you could create address objects for each address and create an address-group that consists of the recorded IPs. Whenever that script runs you simply take the last recorded results and remove them, rebuild the list via the current pulled results, and then schedule a commit so that you keep the address-group clean of unused addresses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 20:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245595#M69976</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-10T20:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN cache limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245597#M69977</link>
      <description>&lt;P&gt;Solution 6.1# Script it and use dynamic address groups. This way you don't need to commit changes as they will be active immediately:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 20:44:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-cache-limitations/m-p/245597#M69977</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-01-10T20:44:48Z</dc:date>
    </item>
  </channel>
</rss>

