<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Dual Action on Same Malicious Domain in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380631#M89683</link>
    <description>&lt;P&gt;We have found in the logs, Malicious DNS queries are being blocked but few of them are in Alert State. however the Domain is marked as a malicious in DNS signature at Threat Vault.&lt;/P&gt;&lt;P&gt;Can you please elaborate why paloalto having dual action on same malicious domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_0-1610996825658.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29585i6470139578F2D455/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_0-1610996825658.png" alt="Joshan_Lakhani_0-1610996825658.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2021 19:08:16 GMT</pubDate>
    <dc:creator>Joshan_Lakhani</dc:creator>
    <dc:date>2021-01-18T19:08:16Z</dc:date>
    <item>
      <title>Palo Dual Action on Same Malicious Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380631#M89683</link>
      <description>&lt;P&gt;We have found in the logs, Malicious DNS queries are being blocked but few of them are in Alert State. however the Domain is marked as a malicious in DNS signature at Threat Vault.&lt;/P&gt;&lt;P&gt;Can you please elaborate why paloalto having dual action on same malicious domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_0-1610996825658.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29585i6470139578F2D455/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_0-1610996825658.png" alt="Joshan_Lakhani_0-1610996825658.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 19:08:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380631#M89683</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2021-01-18T19:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Dual Action on Same Malicious Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380672#M89684</link>
      <description>&lt;P&gt;do you happen to have multiple vsys or could these 'alert' ones be hitting a different rule altogether ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 22:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380672#M89684</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-18T22:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Dual Action on Same Malicious Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380707#M89690</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;we are not using Vsys moreover it's&amp;nbsp; hit on same policy. Furthermore when we check the other domains we are still see that some time paloalto it's show alert and 90% is sinkhole please suggest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 06:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/380707#M89690</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2021-01-19T06:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Dual Action on Same Malicious Domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/381710#M89766</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18087"&gt;@MP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our case, if the get the IP address of the malicious domain and it generates the “alert” on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_0-1611346021358.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29636iFB9DB29D1C6F878C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_0-1611346021358.png" alt="Joshan_Lakhani_0-1611346021358.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_1-1611346021362.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29635iEC2FAB887FFF6062/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_1-1611346021362.png" alt="Joshan_Lakhani_1-1611346021362.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One the second time it will identify its malicious domain then the query will send to the sinkhole.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_2-1611346035015.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29637i0422129F59CFB3C6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_2-1611346035015.png" alt="Joshan_Lakhani_2-1611346035015.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Joshan_Lakhani_3-1611346035018.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29638i4229F8FF11776C3F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Joshan_Lakhani_3-1611346035018.png" alt="Joshan_Lakhani_3-1611346035018.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS sinkhole can be used to identify infected hosts on a&amp;nbsp;network where there is an internal DNS Server in-route to the firewall that causes the reference of the original source IP address of the host that first originated the query to be lost (the query is received by the Internal DNS Server, and the internal DNS Server sources a new query if the name-to-IP resolution is not locally cached).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The things we have understood by your assistance but we could not found any document having the same use case or actual flow of DNS or &lt;STRONG&gt;its cache&lt;/STRONG&gt; how they works.&lt;/P&gt;&lt;P&gt;Can&amp;nbsp; you please suggest any document or use case.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 20:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-dual-action-on-same-malicious-domain/m-p/381710#M89766</guid>
      <dc:creator>Joshan_Lakhani</dc:creator>
      <dc:date>2021-01-22T20:09:45Z</dc:date>
    </item>
  </channel>
</rss>

