<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS setup best practice in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/339397#M85235</link>
    <description>&lt;P&gt;Hi All ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am planning to use FQDN based address for security policy&amp;nbsp; . Any&amp;nbsp;&lt;/P&gt;&lt;P&gt;best practice to follow . As we have concern related to FQDN dns cache on firewall . And if we are connecting to cloud ( using hybrid setup)&amp;nbsp; any specific recommendation for that as well .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jul 2020 10:00:24 GMT</pubDate>
    <dc:creator>deepak12</dc:creator>
    <dc:date>2020-07-18T10:00:24Z</dc:date>
    <item>
      <title>DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/339397#M85235</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am planning to use FQDN based address for security policy&amp;nbsp; . Any&amp;nbsp;&lt;/P&gt;&lt;P&gt;best practice to follow . As we have concern related to FQDN dns cache on firewall . And if we are connecting to cloud ( using hybrid setup)&amp;nbsp; any specific recommendation for that as well .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 10:00:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/339397#M85235</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-18T10:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/339411#M85236</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HI&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please give any suggestion here .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks ..&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 15:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/339411#M85236</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-18T15:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340060#M85368</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104297"&gt;@deepak12&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are no as such best practice to follow. The only thing you need to consider is DNS configuration on the firewall. As when FQDN based object is configured on firewall, the MGMT plane sends DNS query requests to the configured DNS servers and populates all the IP addresses associated with configured FQDN object. These IP addresses are then forwarded to dataplane and act according to the security policy actions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here for Dataplane, this object only acts as a IP address but not as FQDN/domain. There is limit of max 10 IP addresses which are mapped by firewall to one FQDN object. There's no way to modify this limit. In this type of object, you cant configure wildcard domain. For wildcard domains, custom URL category it the option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 14:45:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340060#M85368</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-07-22T14:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340061#M85369</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Hi Mayur ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help. My concern was mainly due to FQDN cache on firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one more question.supoose we have fqdn along with Uri path like &lt;A href="https://abc.company.com/check/folder" target="_blank"&gt;https://abc.company.com/check/folder&lt;/A&gt;..&lt;/P&gt;&lt;P&gt;For this case just using fqdn based address will work or need to go for custom url for this as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 14:52:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340061#M85369</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-22T14:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340230#M85395</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104297"&gt;@deepak12&lt;/a&gt;It will work.&lt;/P&gt;&lt;P&gt;For data plane request for &lt;A href="https://abc.company.com/check/folder" target="_blank" rel="nofollow noopener noreferrer noopener noreferrer"&gt;https://abc.company.com/check/folder&lt;/A&gt;.. will get as &lt;A href="https://abc.company.com/check/folder" target="_blank" rel="nofollow noopener noreferrer noopener noreferrer"&gt;https://&amp;lt;FQDN-IP-Address&amp;gt;/check/folder&lt;/A&gt;..&lt;/P&gt;&lt;P&gt;You only need to add object without https:// and any URI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 06:36:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340230#M85395</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-07-23T06:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340335#M85428</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help ...&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 14:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/340335#M85428</guid>
      <dc:creator>deepak12</dc:creator>
      <dc:date>2020-07-23T14:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNS setup best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/568942#M114789</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;Also use a secure DNS provider as an added layer.&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=ROIAYSEbTuo" target="_blank"&gt;https://www.youtube.com/watch?v=ROIAYSEbTuo&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 20:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-setup-best-practice/m-p/568942#M114789</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-12-07T20:35:07Z</dc:date>
    </item>
  </channel>
</rss>

