<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How Palo Alto enabled with DNS Sinkhole will see original Client IP Address; when internal DNS server working in Recurisive mode? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-enabled-with-dns-sinkhole-will-see-original-client/m-p/384674#M90064</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need help in solution to know how actually Palo Alto enabled with DNS Sinkhole will see original client IP Address making DNS request to a domain in DNS sinkhole list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More Information is:&lt;/P&gt;&lt;P&gt;My client computer with IP address (10.10.10.10) configured with Internal DNS server with IP Address (10.10.10.20). Internal DNS server working in the recursive mode so if it does not have DNS answer; it will send DNS queries to TLDs to get an answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For both my client computer and internal DNS server, Gateway is Palo Alto Next-Generation Firewall with Gateway address 10.10.10.1&lt;/P&gt;&lt;P&gt;I have enabled DNS Sinkhole to domain query lets say example.com to 10.10.10.254.&lt;/P&gt;&lt;P&gt;Now in this setup how my Palo Alto firewall will identify who was original client requested for example.com because we know DNS server will send DNS request with its own source IP address to the Internet and not with original Client IP Address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Feb 2021 03:05:27 GMT</pubDate>
    <dc:creator>ankush3597</dc:creator>
    <dc:date>2021-02-09T03:05:27Z</dc:date>
    <item>
      <title>How Palo Alto enabled with DNS Sinkhole will see original Client IP Address; when internal DNS server working in Recurisive mode?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-enabled-with-dns-sinkhole-will-see-original-client/m-p/384674#M90064</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need help in solution to know how actually Palo Alto enabled with DNS Sinkhole will see original client IP Address making DNS request to a domain in DNS sinkhole list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More Information is:&lt;/P&gt;&lt;P&gt;My client computer with IP address (10.10.10.10) configured with Internal DNS server with IP Address (10.10.10.20). Internal DNS server working in the recursive mode so if it does not have DNS answer; it will send DNS queries to TLDs to get an answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For both my client computer and internal DNS server, Gateway is Palo Alto Next-Generation Firewall with Gateway address 10.10.10.1&lt;/P&gt;&lt;P&gt;I have enabled DNS Sinkhole to domain query lets say example.com to 10.10.10.254.&lt;/P&gt;&lt;P&gt;Now in this setup how my Palo Alto firewall will identify who was original client requested for example.com because we know DNS server will send DNS request with its own source IP address to the Internet and not with original Client IP Address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 03:05:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-enabled-with-dns-sinkhole-will-see-original-client/m-p/384674#M90064</guid>
      <dc:creator>ankush3597</dc:creator>
      <dc:date>2021-02-09T03:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: How Palo Alto enabled with DNS Sinkhole will see original Client IP Address; when internal DNS server working in Recurisive mode?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-enabled-with-dns-sinkhole-will-see-original-client/m-p/384721#M90067</link>
      <description>&lt;P&gt;Sinkhole will 'poison' the DNS reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so usually the client sends a dns request to the internal dns, the internal dns then requests the information from the TLD, the tld replies with an IP address&amp;nbsp; for the A/AAAA record, and the Palo Alto will then replace the IP with the sinkhole IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the internal DNS relays the poisoned answer to the client and the client then tries to connect to the sinkhole IP, this is how you know the client was the original requestor&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 08:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-palo-alto-enabled-with-dns-sinkhole-will-see-original-client/m-p/384721#M90067</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-09T08:35:46Z</dc:date>
    </item>
  </channel>
</rss>

