<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Query in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344034#M86091</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Thanks for your reply&lt;/P&gt;&lt;P&gt;I want to configure like this in cisco dns-guard Like that firewall will allow only one response for one dns request packet. So Can we configure this in our palo alto firewall.&lt;/P&gt;</description>
    <pubDate>Sat, 15 Aug 2020 15:48:34 GMT</pubDate>
    <dc:creator>Joshan_Lakhani</dc:creator>
    <dc:date>2020-08-15T15:48:34Z</dc:date>
    <item>
      <title>DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344019#M86084</link>
      <description>&lt;P&gt;Can we configure&amp;nbsp;firewall will allow only one response for one dns request packet. Please suggest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 13:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344019#M86084</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-15T13:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344031#M86089</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130663"&gt;@Joshan_Lakhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see two possibilities to do this:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure the DNS proxy feature to only correctly resolve this one dns entry you need (the client/server then needs to have this dns proxy IP configured as DNS server)&lt;/LI&gt;
&lt;LI&gt;Create a custom application signature where you specify the DNS entry that you want to allow&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sat, 15 Aug 2020 15:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344031#M86089</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-15T15:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344033#M86090</link>
      <description>&lt;P&gt;I want to configure like this in cisco dns-guard Like that firewall will allow only one response for one dns request packet. So Can we configure this in our palo alto firewall.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 15:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344033#M86090</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-15T15:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344034#M86091</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Thanks for your reply&lt;/P&gt;&lt;P&gt;I want to configure like this in cisco dns-guard Like that firewall will allow only one response for one dns request packet. So Can we configure this in our palo alto firewall.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 15:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344034#M86091</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-15T15:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344038#M86092</link>
      <description>&lt;P&gt;Ok, so for example when a client asks for &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; you want only &lt;STRONG&gt;one&lt;/STRONG&gt; IP as response? If I understood now correctly, then no, this is not possible.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 16:20:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344038#M86092</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-15T16:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344247#M86130</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;It might help if we understood the reasoning behind the question, i.e. we want to do this because.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition to enabling DNS-Proxy, please make sure to configure and enable all the security features including the dns sinkhle.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 21:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344247#M86130</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-08-17T21:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344454#M86178</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;thanks for you reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we observed some time users are access yahoo.com instead of this user will also get other response too like shopping site, advertising page etc.. so can we prevent the user to access only&amp;nbsp; yahoo.com rather then add some other DNS query resolution . Please suggest&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 19:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344454#M86178</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-18T19:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344476#M86180</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I think I am understanding now. If you go to a site like yahoo.com, that person will be seen as going to many different sites and categories. This is due to the nature of the destination site as the main site maybe 1 category, but since the site is dynamic and pulls in other sites to display content, you will see other things, i.e. advertising. So if you block advertising, you will start to see your block page appearing in little places where that particular dynamic content is getting pulled in from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see from the screen shot there is a blank spot on the right where an 'Ad' is supposed to be displayed. However we block them for several reasons.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1597785366518.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27428i1693DFB333A49EDB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1597785366518.png" alt="OtakarKlier_0-1597785366518.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that makes sense&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 21:16:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344476#M86180</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-08-18T21:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344525#M86190</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a little correction here: No, we do not want single IP in response of a domain resolution – a single response can have multiple IP addresses. What we want to achieve is, whenever a client requests DNS server for a DNS query Palo Alto should ensure it gets a single response. We basically want to prevent DDOS attacks that are initiated using DNS responses.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 05:52:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344525#M86190</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-19T05:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344567#M86203</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thanks for that clarification. I would recommend following the Palo Alto best practice and configure a DoS protection policy along with the Zone Protection policy.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOICA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClOICA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 14:17:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344567#M86203</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-08-19T14:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344602#M86210</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;Thanks for you reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the issue is when user send his request to DNS. palolalto resolve one one DNS query rather than i will contact with other DNS traffic also. Some can we pervent for multiple DNS response&amp;nbsp; for single query.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 19:37:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-query/m-p/344602#M86210</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2020-08-19T19:37:20Z</dc:date>
    </item>
  </channel>
</rss>

