<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FQDN object not resolved in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378594#M89497</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have this fqdn object created:&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-01-08 12:26:14.872 +0100 dnscfgmod: Fqdn SIEMENS OWNCLOUD SERVER/cco.siemens.com could not be resolved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i run a ping from MGMT A interface is resolving:&lt;/P&gt;&lt;P&gt;ping host cco.siemens.com&lt;BR /&gt;PING cco.siemens.com (&lt;STRONG&gt;212.231.11.154&lt;/STRONG&gt;) 56(84) bytes of data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS is OK, reachable, and resolving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i go to the web and clik solve in the object is also resolving:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns.JPG" style="width: 593px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29436i2380110B33199219/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns.JPG" alt="dns.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in FQDN list is not resolving so the rule is not applying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;request system fqdn show:&lt;/P&gt;&lt;P&gt;cco.siemens.com (Objectname SIEMENS SERVER):&lt;/P&gt;&lt;P&gt;Not resolved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WHy is happening this? any file to check deep tshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jan 2021 12:44:26 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2021-01-08T12:44:26Z</dc:date>
    <item>
      <title>FQDN object not resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378594#M89497</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have this fqdn object created:&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-01-08 12:26:14.872 +0100 dnscfgmod: Fqdn SIEMENS OWNCLOUD SERVER/cco.siemens.com could not be resolved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i run a ping from MGMT A interface is resolving:&lt;/P&gt;&lt;P&gt;ping host cco.siemens.com&lt;BR /&gt;PING cco.siemens.com (&lt;STRONG&gt;212.231.11.154&lt;/STRONG&gt;) 56(84) bytes of data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS is OK, reachable, and resolving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i go to the web and clik solve in the object is also resolving:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns.JPG" style="width: 593px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29436i2380110B33199219/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns.JPG" alt="dns.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in FQDN list is not resolving so the rule is not applying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;request system fqdn show:&lt;/P&gt;&lt;P&gt;cco.siemens.com (Objectname SIEMENS SERVER):&lt;/P&gt;&lt;P&gt;Not resolved&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WHy is happening this? any file to check deep tshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 12:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378594#M89497</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-01-08T12:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN object not resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378792#M89513</link>
      <description>&lt;P&gt;Which PAN OS you are running?&lt;/P&gt;
&lt;P&gt;Do you have issue only with this FQDN or other FQDN's also?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me it is resolving&lt;/P&gt;
&lt;P&gt;show dns-proxy fqdn all&lt;/P&gt;
&lt;P&gt;FQDN Table : Request time 2021-01-09 20:56:53&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;IP Address&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;VSYS : (using mgmt-obj dnsproxy object)&lt;BR /&gt;Shared&lt;BR /&gt;vsys1&lt;/P&gt;
&lt;P&gt;cco.siemens.com&lt;BR /&gt;212.231.11.154&lt;BR /&gt;:: unknown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally this happens if IP in Security Rule does not match the FQDN IP address.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sometimes&amp;nbsp; FQDN object&amp;nbsp; not refreshing properly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also Check traffic logs to see which rule it is hitting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Double check your security policy rule.&lt;/P&gt;
&lt;P&gt;Also try this from CLI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;request system fqdn refresh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2021 21:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378792#M89513</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-01-09T21:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN object not resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378889#M89524</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PanOS is old, we will upgrade during this month. Current PanOS is 8.0.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We dont use dns-proxy. We run command: request system fqdn show&amp;nbsp;&lt;/P&gt;&lt;P&gt;in order to see the fqdn resolved&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 08:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/378889#M89524</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-01-11T08:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN object not resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/522770#M108284</link>
      <description>&lt;P&gt;I had the same issue; support fixed it by running the below commands, commands only impact management plane but not impacting the actual traffic, we did it during business hours without impact to the users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; debug software restart process device-server&lt;BR /&gt;&amp;gt; debug software restart process management-server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this help.&lt;/P&gt;
&lt;P&gt;Mustafa&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 19:00:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/522770#M108284</guid>
      <dc:creator>Mustafa83</dc:creator>
      <dc:date>2022-11-29T19:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: FQDN object not resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/526252#M108778</link>
      <description>&lt;P&gt;This seems like a bug that causes crashes or/and memory leaks and till it is fixed maybe you can run a script using tools like Ansible or XSOAR to periodically restart the process or the managment plane:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://paloaltonetworks.github.io/pan-os-ansible/modules/panos_op_module.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://paloaltonetworks.github.io/pan-os-ansible/modules/panos_op_module.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/panorama" target="_blank" rel="noopener nofollow noreferrer"&gt;https://xsoar.pan.dev/docs/reference/integrations/panorama&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2023 09:04:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fqdn-object-not-resolved/m-p/526252#M108778</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-08T09:04:00Z</dc:date>
    </item>
  </channel>
</rss>

