<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent my firewall to stop responding to external DNS queries in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376285#M89279</link>
    <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;I did some testing and prove that the response is not happening by our firewall .&lt;/P&gt;&lt;P&gt;it is bad behavior from the vpn application.&lt;/P&gt;&lt;P&gt;thanks for all&lt;/P&gt;</description>
    <pubDate>Sat, 26 Dec 2020 10:30:21 GMT</pubDate>
    <dc:creator>engreda22</dc:creator>
    <dc:date>2020-12-26T10:30:21Z</dc:date>
    <item>
      <title>How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375645#M89203</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;currently if anyone from public network uses the external IP of the firewall as a DNS server and try to send DNS query , my&amp;nbsp; FW is responding to that queries which is high risk .&lt;/P&gt;&lt;P&gt;how to stop FW from responding to any DNS queries knowing that the DNS proxy is not configured and our DNS security subscription is expired .&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 21:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375645#M89203</guid>
      <dc:creator>engreda22</dc:creator>
      <dc:date>2020-12-21T21:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375698#M89206</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sounds like you have sinkhole functionality enabled under the Anti Spyware Profile.&lt;/P&gt;
&lt;P&gt;Double check and advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am also trying to determine why your config has the DNS server for your company pointed to the FW (as if perhaps DHCP is enabled on FW).. That can be confirmed by Network tab, then DHCP Server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Else, you could try a test and manually configure a client to NOT use the FW (changing the DNS server on the computer)&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 22:12:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375698#M89206</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-12-21T22:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375799#M89218</link>
      <description>&lt;P&gt;Thanks Steve for your response&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually it is part of penetration testing like from public network we tried nslookup with our fw ip address and it responded .&lt;/P&gt;&lt;P&gt;Antispayware profile is not applied to any policy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 11:16:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375799#M89218</guid>
      <dc:creator>engreda22</dc:creator>
      <dc:date>2020-12-22T11:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375825#M89224</link>
      <description>&lt;P&gt;It will be responding because you haven't specifically blocked the traffic and intrazone traffic is allowed by default. Just set up a rule that blocks outside-to-outside traffic on UDP 53 and that should stop it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set up rules to deny all inbound traffic that isn't on the specific ports I'm expecting, just to reduce a bit of CPU load.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 16:03:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/375825#M89224</guid>
      <dc:creator>CoreHR</dc:creator>
      <dc:date>2020-12-22T16:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376069#M89253</link>
      <description>&lt;P&gt;Actually the issue raised only when the user is connected to VPN (like hotspot)&amp;nbsp;&lt;/P&gt;&lt;P&gt;for any other situation it is not responding&amp;nbsp;&lt;/P&gt;&lt;P&gt;so it something happens through the vpn tunnel only.&lt;/P&gt;&lt;P&gt;have you tried that ?&lt;/P&gt;&lt;P&gt;connected to any vpn (not corporate vpn) then do nslookup with external ip of your firewall and check if it will reply or not&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 17:53:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376069#M89253</guid>
      <dc:creator>engreda22</dc:creator>
      <dc:date>2020-12-23T17:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376163#M89270</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/166220"&gt;@engreda22&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my understanding &amp;nbsp;your issue is that if someone does nslookup for the firewall &amp;nbsp;public ip then it should not resolve right?&lt;/P&gt;
&lt;P&gt;This depends on your DNS server where you have a host or A record entry &amp;nbsp;for your firewall hostname and Public IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It also depends if you have your firewall public IP used for VPN etc then you need your firewall need to resolve it.&lt;/P&gt;
&lt;P&gt;In our company we have firewall public IP address that is used for natting and external connections coming from Internet to our public&lt;/P&gt;
&lt;P&gt;facing apps but those IP does not resolve as we have our own DNS server with Internal and External Zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also we have Global Protect VPN that has public IP address and that address gets resolve as we need that to make VPN work.&lt;/P&gt;
&lt;P&gt;Also we have DNS entry for our firewall VPN hostname with Public IP address in our DNS External zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if you have any more questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Dec 2020 05:10:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376163#M89270</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-12-25T05:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent my firewall to stop responding to external DNS queries</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376285#M89279</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;I did some testing and prove that the response is not happening by our firewall .&lt;/P&gt;&lt;P&gt;it is bad behavior from the vpn application.&lt;/P&gt;&lt;P&gt;thanks for all&lt;/P&gt;</description>
      <pubDate>Sat, 26 Dec 2020 10:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-my-firewall-to-stop-responding-to-external-dns/m-p/376285#M89279</guid>
      <dc:creator>engreda22</dc:creator>
      <dc:date>2020-12-26T10:30:21Z</dc:date>
    </item>
  </channel>
</rss>

