<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS queries to resolve internal hosts from PA managment IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332733#M84101</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see my firewall is sending DNS requests ( request for A record) to resolve some of internal hostnames.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I dont have GP/detect internal host configured&lt;/LI&gt;&lt;LI&gt;I dont have FQDN objects with these hostnames&lt;/LI&gt;&lt;LI&gt;I have exported and checked entire config, the firewall is not having this hostname in the configuration&lt;/LI&gt;&lt;LI&gt;It is requesting for A record ( so 'resolve hostname' is not causing it.&lt;/LI&gt;&lt;LI&gt;Dont have DNS proxy configured in firewall&lt;/LI&gt;&lt;LI&gt;This are internal hostnames, not malicious, which rule out DNS queries because of HTTP/TLS evasion&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This looks like firewall is trying to resolve in real time. I understands that firewall will be using DNS for&amp;nbsp;&lt;SPAN&gt;reporting, management services (such as email, Kerberos, SNMP, syslog) as per document. But not sure because of which of this reason firewall is trying to resolve these internal hostnames. It would be helpful if anybody can answer this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance !&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2020 07:50:45 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2020-06-10T07:50:45Z</dc:date>
    <item>
      <title>DNS queries to resolve internal hosts from PA managment IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332733#M84101</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see my firewall is sending DNS requests ( request for A record) to resolve some of internal hostnames.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I dont have GP/detect internal host configured&lt;/LI&gt;&lt;LI&gt;I dont have FQDN objects with these hostnames&lt;/LI&gt;&lt;LI&gt;I have exported and checked entire config, the firewall is not having this hostname in the configuration&lt;/LI&gt;&lt;LI&gt;It is requesting for A record ( so 'resolve hostname' is not causing it.&lt;/LI&gt;&lt;LI&gt;Dont have DNS proxy configured in firewall&lt;/LI&gt;&lt;LI&gt;This are internal hostnames, not malicious, which rule out DNS queries because of HTTP/TLS evasion&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This looks like firewall is trying to resolve in real time. I understands that firewall will be using DNS for&amp;nbsp;&lt;SPAN&gt;reporting, management services (such as email, Kerberos, SNMP, syslog) as per document. But not sure because of which of this reason firewall is trying to resolve these internal hostnames. It would be helpful if anybody can answer this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance !&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 07:50:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332733#M84101</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-06-10T07:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS queries to resolve internal hosts from PA managment IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332798#M84113</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101029"&gt;@Abdul_Razaq&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you have WMI probing enabled within User Identification?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 14:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332798#M84113</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-10T14:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: DNS queries to resolve internal hosts from PA managment IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332804#M84114</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;&lt;P&gt;I thought of this possibility as&amp;nbsp;WMI probing is enabled, but as the user IP mapping entries will be IP address, i don't see a need for PA to do a DNS query for device hostnames other than the hostname of AD servers.&lt;/P&gt;&lt;P&gt;I am wondering if there is any two way of verification to find the hostname of an IP, then a DNS query for A record for verifying it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 14:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/332804#M84114</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-06-10T14:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNS queries to resolve internal hosts from PA managment IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/336220#M84701</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody have any though on this.. i can see the DNS query for only couple of servers (it should not be for WMI i feel as i can see it only for very less endpoints directly connected to firewall). I am even confused how firewall got this hostname in first place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 06:01:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-queries-to-resolve-internal-hosts-from-pa-managment-ip/m-p/336220#M84701</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-07-01T06:01:15Z</dc:date>
    </item>
  </channel>
</rss>

