<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS is changing? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246799#M70265</link>
    <description>&lt;P&gt;Anybody has hear about it and are PA firewalls effected by it. It seems they are making some changes to its functioning. Does PA application supports the said change?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;https://dnsflagday.net&lt;BR /&gt;&lt;BR /&gt;______________________________
What is happening?
The current&amp;nbsp;DNS&amp;nbsp;is unnecessarily slow and suffers from inability to deploy new features. To remediate these problems,&amp;nbsp;vendors of DNS software&amp;nbsp;and also big&amp;nbsp;public DNS providers&amp;nbsp;are going to remove certain workarounds on February 1st, 2019.
This change affects only sites which operate software which is not following published standards. Are you affected?
______________________________&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jan 2019 15:48:24 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2019-01-21T15:48:24Z</dc:date>
    <item>
      <title>DNS is changing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246799#M70265</link>
      <description>&lt;P&gt;Anybody has hear about it and are PA firewalls effected by it. It seems they are making some changes to its functioning. Does PA application supports the said change?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;https://dnsflagday.net&lt;BR /&gt;&lt;BR /&gt;______________________________
What is happening?
The current&amp;nbsp;DNS&amp;nbsp;is unnecessarily slow and suffers from inability to deploy new features. To remediate these problems,&amp;nbsp;vendors of DNS software&amp;nbsp;and also big&amp;nbsp;public DNS providers&amp;nbsp;are going to remove certain workarounds on February 1st, 2019.
This change affects only sites which operate software which is not following published standards. Are you affected?
______________________________&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 15:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246799#M70265</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2019-01-21T15:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS is changing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246979#M70309</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I think as long as you point to a reputable DNS provider, you should be OK. If you run your own, then this might affect you. A good free DNS service that also provides some DNS protection is opendns.com. I dont work for them but love what they are doing on a DNS level.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 16:58:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246979#M70309</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-01-22T16:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: DNS is changing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246991#M70311</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Anybody has hear about it and are PA firewalls effected by it. It seems they are making some changes to its functioning. Does PA application supports the said change?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;https://dnsflagday.net&lt;BR /&gt;&lt;BR /&gt;______________________________
What is happening?
The current&amp;nbsp;DNS&amp;nbsp;is unnecessarily slow and suffers from inability to deploy new features. To remediate these problems,&amp;nbsp;vendors of DNS software&amp;nbsp;and also big&amp;nbsp;public DNS providers&amp;nbsp;are going to remove certain workarounds on February 1st, 2019.
This change affects only sites which operate software which is not following published standards. Are you affected?
______________________________&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your post doesn't really refer to anything for us to go off of.&amp;nbsp; Some Googleing I found this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.reddit.com/r/sysadmin/comments/agqdkf/dns_flag_day_on_february_1_2019_check_your_domains/" target="_blank"&gt;https://www.reddit.com/r/sysadmin/comments/agqdkf/dns_flag_day_on_february_1_2019_check_your_domains/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not really sure how this will have any effect on Palo Alto as a product.&amp;nbsp; This seems to have more to do with how DNS administrators configure their enviornment.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/246991#M70311</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-01-22T17:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS is changing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/247940#M70541</link>
      <description>&lt;P&gt;In short, DNS flag day is about dropping support for communicating with broken "DNS servers" that don't support EDNS (one feature of which is support for DNS within UDP packets of size &amp;gt; 512 bytes) - there are currently work-arounds in place that slow down DNS. As support for EDNS has been around for years, it's time the work-arounds were dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As an indication of how old this stuff is, I recall testing that EDNS support worked when I rolled out a Cisco FWSM back in 2004/5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might run into trouble if you're running authorititative DNS servers :-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) On really ancient DNS software (Microsoft DNS has been mentioned although I suspect they're talking about NT4 era)&lt;/P&gt;&lt;P&gt;b) Behind a broken firewall that assumes that DNS packets &amp;gt; 512 bytes is in error. For anything released in the last 5 years this would probably mean a deliberate configuration choice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running some of my authorititative DNS servers behind PA firewalls and have tested them for complience a couple of days ago - no issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 10:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-is-changing/m-p/247940#M70541</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2019-01-29T10:14:48Z</dc:date>
    </item>
  </channel>
</rss>

