<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Passive firewall DNS request in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11437#M8423</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you also see the content of the DNS requests? It is possible that these are requests to resolve updates.paloaltonetworks.com, and that it keeps on trying to resolve this if it is not getting a response.&lt;/P&gt;&lt;P&gt;The secondary firewall will also try to do updates, if it is configured to do this (Device - Dynamic updates)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Mar 2014 13:44:21 GMT</pubDate>
    <dc:creator>${userLoginName}</dc:creator>
    <dc:date>2014-03-18T13:44:21Z</dc:date>
    <item>
      <title>Passive firewall DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11434#M8420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a cluster PA (active/passive), and checking the logs we realised that PA passive is sending DNS connections to its DNS configure like secondary. Shouldnt do this connection only the active PA???? why the passive is doing this request DNS being the passive firewall???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Jesus C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 06:34:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11434#M8420</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-02-24T06:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11435#M8421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jesus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope your Passive firewall's management interface connected with your network. For example: if you try to download the dynamic updates on your passive firewall, it will send a DNS request for updates.paloaltonetwork.com to resolve it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please verify what request the Passive node is sending to your DNS server...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 07:03:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11435#M8421</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-24T07:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11436#M8422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is our config in the palo alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #1f497d;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS services&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;PA-2050-10.84.96.115 PA-01(active)&amp;nbsp; &lt;/SPAN&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;Primary DNS Server 146.219.39.201 &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;Secondary DNS Server 146.219.39.202 &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;PA-2050-10.84.96.116 PA-02(passive) &lt;/SPAN&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;Primary DNS Server 192.168.1.1&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;Secondary DNS Server &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;194.179.1.121&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So i can see in the logs in FW1 (active), that there is a connection from management interface FW2 (10.84.96.116) to destination its DNS secondary 194.179.1.121........why does FW2 do this connection?? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I attach the logs in FW1&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;IMG __jive_id="11746" alt="log FW1.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11746_log FW1.jpg" style="width: 620px; height: 200px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;A tool in the DNS server is detecting these request like a attack....&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 70.8pt;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Arial Narrow','sans-serif'; color: #1f497d;"&gt;…&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 07:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11436#M8422</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-02-24T07:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11437#M8423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you also see the content of the DNS requests? It is possible that these are requests to resolve updates.paloaltonetworks.com, and that it keeps on trying to resolve this if it is not getting a response.&lt;/P&gt;&lt;P&gt;The secondary firewall will also try to do updates, if it is configured to do this (Device - Dynamic updates)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2014 13:44:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11437#M8423</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2014-03-18T13:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Passive firewall DNS request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11438#M8424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/21905"&gt;COS&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we look at the packet capture for the DNS request we can know to what domain the request is happening. If the domain is fake / repetitive / in excess then it can be termed an attack or so. If the domains are genuine and if they are related to paloalto then it is normal.&lt;/P&gt;&lt;P&gt;( Apps and Threat updates, software updates, url database updates and so on )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will have to find what kind of request is going for the dns server based on that we can configure the firewall management interface to either fetch that data or deny. For instance if Dynamic updates are not needed then we can set the schedule to none so that it does not fetch the content updates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We see that all the request to the DNS server is from the management interface. If this is not needed then through the service routes you can customize it to go through any other data ports or probably block traffic on path or remove routes to the dns and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2014 14:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passive-firewall-dns-request/m-p/11438#M8424</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-03-18T14:30:27Z</dc:date>
    </item>
  </channel>
</rss>

