<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS proxy sharepoint domain issue when cache enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/361505#M88190</link>
    <description>&lt;P&gt;Hi there, i have some issues with my firewall when using dns-proxy with enabled cache. I cannot resolve sharepoint domains e.g. bitmix.sharepoint.com, but when I disable the cacheoption everything works fine.&lt;BR /&gt;Does someone have any suggestion how I could solve this?&lt;BR /&gt;I'm using PanOS 10.0.2&lt;/P&gt;</description>
    <pubDate>Sun, 08 Nov 2020 07:20:01 GMT</pubDate>
    <dc:creator>Chris.Ka</dc:creator>
    <dc:date>2020-11-08T07:20:01Z</dc:date>
    <item>
      <title>DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/361505#M88190</link>
      <description>&lt;P&gt;Hi there, i have some issues with my firewall when using dns-proxy with enabled cache. I cannot resolve sharepoint domains e.g. bitmix.sharepoint.com, but when I disable the cacheoption everything works fine.&lt;BR /&gt;Does someone have any suggestion how I could solve this?&lt;BR /&gt;I'm using PanOS 10.0.2&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 07:20:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/361505#M88190</guid>
      <dc:creator>Chris.Ka</dc:creator>
      <dc:date>2020-11-08T07:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/361540#M88197</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/96349"&gt;@Chris.Ka&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Open a TAC case and ask them to replicate the issue. Sounds you you've possibly found a PAN-OS 10 bug.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI,&lt;/P&gt;
&lt;P&gt;Unless you need to run PAN-OS 10 due a feature set, I wouldn't recommend running it yet on production gear. I'd stick with PAN-OS 9.1 for anything production related.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 18:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/361540#M88197</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-08T18:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/364847#M88517</link>
      <description>&lt;P&gt;I do notice the same issue. Did they found the root cause? If not I would also open a ticket to help them finding the roort cause.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 13:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/364847#M88517</guid>
      <dc:creator>kevin_thys</dc:creator>
      <dc:date>2020-11-23T13:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/381794#M89771</link>
      <description>&lt;P&gt;Also "dns cache" should be applied at the "proxy rule" level, not the parent layer.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 10:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/381794#M89771</guid>
      <dc:creator>jmretting</dc:creator>
      <dc:date>2021-01-24T10:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/383370#M89950</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/96349"&gt;@Chris.Ka&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi there, i have some issues with my firewall when using dns-proxy with enabled cache. I cannot resolve sharepoint domains e.g. bitmix.sharepoint.com, but when I disable the cacheoption everything works fine.&lt;BR /&gt;Does someone have any suggestion how I could solve this?&amp;nbsp;&lt;FONT face="comic sans ms,sans-serif" size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;&lt;A href="https://www.mygroundbiz.club/" target="_self"&gt;mybizaccount&lt;/A&gt;&lt;/FONT&gt;&lt;BR /&gt;I'm using PanOS 10.0.2&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;I think I am also facing this issue. but&amp;nbsp;Thanks for the information.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 08:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/383370#M89950</guid>
      <dc:creator>TerryStevens</dc:creator>
      <dc:date>2021-02-04T08:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389641#M90636</link>
      <description>&lt;P&gt;Same issue found on 10.0.4&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 03:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389641#M90636</guid>
      <dc:creator>DavidRees_Imdex</dc:creator>
      <dc:date>2021-03-08T03:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389648#M90637</link>
      <description>&lt;P&gt;I have found that PA management DNS fails if Cache is disabled on the DNS Proxy. I needed to break out DNS management interface from a bug fixed DNS proxy with cache disabled. And then enable cache and replicate any dns/static rules. I have identified *.intuit.com and *.sharepoint.com. Applying non-cache enabled rules for those domains in your DNS proxy will fix failing lookups. However I don't know if there is any reasonable way to determine what FQDN's are affects. In which case....DNS Proxy cache should not be used on version 10 in any production environment. Needing to enable cache on the managment interface for DNS also means there is no way to apply firewall policies regarding those afflicted unknown/known FQDNs. v10 is not production ready. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 04:24:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389648#M90637</guid>
      <dc:creator>morgnercoit</dc:creator>
      <dc:date>2021-03-08T04:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389663#M90640</link>
      <description>&lt;P&gt;I have created an support case for this issue and its a known issue. Here is the important part from the support response:&lt;/P&gt;&lt;P&gt;Root cause:-&lt;/P&gt;&lt;P&gt;When dnsproxy cache is enabled, we always prepare the response from the cache (regardless if we have the records in cache already or we need to forward the request to a name sever first)&lt;BR /&gt;During this process, dnsproxy does not check if the prepared DNS response is too big or not (default udp limit should be 512 bytes). So the DNS response prepared by dnsproxy could be dropped by other PAN FWs or network devices if the size is larger than the limit (512 or otherwise specified in EDNS)&lt;/P&gt;&lt;P&gt;This problem usually happens with nested CNAME records and when cache is used due to dnsproxy's limited compression ability.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As a workaround, one can&lt;BR /&gt;1. disable cache&lt;BR /&gt;2. add DNS proxy rule for this FQDN and not use cache&lt;BR /&gt;3. use EDNS (it allows larger UDP DNS)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 07:18:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389663#M90640</guid>
      <dc:creator>Chris.Ka</dc:creator>
      <dc:date>2021-03-08T07:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389664#M90641</link>
      <description>&lt;P&gt;I have found that if you have a tunnel interface assigned as DNS Service route, and you turn DNS Proxy cache off, resolution fails for all FQDNs.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 07:29:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/389664#M90641</guid>
      <dc:creator>morgnercoit</dc:creator>
      <dc:date>2021-03-08T07:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy sharepoint domain issue when cache enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/394127#M91079</link>
      <description>&lt;P&gt;Looks like its fixed in 10.0.5. Looks like a combination of multiple, from what it looks like, DNS proxy fixes according according release notes.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 05:42:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-sharepoint-domain-issue-when-cache-enabled/m-p/394127#M91079</guid>
      <dc:creator>jmretting</dc:creator>
      <dc:date>2021-03-26T05:42:32Z</dc:date>
    </item>
  </channel>
</rss>

