<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Proxy -  invalid EDNS response in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/394133#M91080</link>
    <description>&lt;P&gt;Thank you all for the feedback. For further testing we will setup a Free DNS Proxy solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would be just easy for our POC in AZURE to use the Palo, but why should it be easy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;One more thing i found out, a DNS request with "dig" works. With DIG the client adds in the request the OPT header and the Palo don't drops the request.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 07:13:05 GMT</pubDate>
    <dc:creator>AKufner</dc:creator>
    <dc:date>2021-03-26T07:13:05Z</dc:date>
    <item>
      <title>DNS Proxy -  invalid EDNS response</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/393326#M91009</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having a issue with the DNS Proxy feature. I'm running a Palo Alto VM (9.1.8) in Azure and want to use the VM as DNS Proxy. As default DNS Server, I want to use AZURE DNS&amp;nbsp;168.63.129.16. Additionally I have some Proxy Rules for internal Domains via VPN to our On Prem Datacenter (DNS).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS Lookups for On Prem are fine, but resolution via AZURE DNS is dropped. Im getting following Error in the DNS Logs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-03-24 15:34:44.629 +0100 Error: pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1563): [AZURE DNS Proxy/42214/19678/Afacebook.com.]:[Drop Rcvd Server Pkt]: invalid EDNS response!&lt;BR /&gt;2021-03-24 15:34:44.629 +0100 Error: pan_dnsproxy_recv_server_udp_cb(pan_dnsproxy_udp.c:222): [udp]: fd 17 from 168.63.129.16 to 0.0.0.0 process server failed!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I captured the Traffic to the AZURE DNS Server. Looks ok for me, the only thing i noticed is that the request querry is missing the additional OPT header.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AKufner_0-1616596994150.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30520i2F52F9B681B16A44/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AKufner_0-1616596994150.png" alt="AKufner_0-1616596994150.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Advice on this issue would be great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 14:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/393326#M91009</guid>
      <dc:creator>AKufner</dc:creator>
      <dc:date>2021-03-24T14:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy -  invalid EDNS response</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/393535#M91026</link>
      <description>&lt;P&gt;The EDNS OPT is described in &lt;A href="https://tools.ietf.org/html/rfc6891" target="_blank"&gt;https://tools.ietf.org/html/rfc6891&lt;/A&gt; and this is extended DNS. There is an article with the same issue :&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/edns0-packet-blocked/td-p/6789" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/edns0-packet-blocked/td-p/6789&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As I don't see for Palo Alto to have made the option to allow EDNS, better check the Azure DNS config or ask their support to stop sending OPT records.Maybe the DNS message is too big or Azure are not following the standard for EDNS very well. The firewall normally should allow EDNS but it will not look at the EDNS data as it is not supported.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Seach the forum as there is much info about EDNS and the OPT and the request for enchancment FR ID : 2315 to Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you see any Anti-Spyware signature under the Threats log for this, you may also stop it. Also test if enabling or disabling "Cache EDNS Responses" on the Firewall DNS proxy config will help. Outside of this check the Azure DNS and with their TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 19:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/393535#M91026</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-24T19:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy -  invalid EDNS response</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/393613#M91033</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When it comes to DNS, I highly recommend a secure DNS provider andnot one that will resolve anything. PaloAlto has one as a subscription, however there are others that are low cost/free you can use, OpenDNS, Quad9, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way you're protected from bad DNS using malware, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://skrzsecurity.net/securedns" target="_blank"&gt;https://skrzsecurity.net/securedns&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 22:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/393613#M91033</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-03-24T22:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy -  invalid EDNS response</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/394133#M91080</link>
      <description>&lt;P&gt;Thank you all for the feedback. For further testing we will setup a Free DNS Proxy solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would be just easy for our POC in AZURE to use the Palo, but why should it be easy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;One more thing i found out, a DNS request with "dig" works. With DIG the client adds in the request the OPT header and the Palo don't drops the request.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 07:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-invalid-edns-response/m-p/394133#M91080</guid>
      <dc:creator>AKufner</dc:creator>
      <dc:date>2021-03-26T07:13:05Z</dc:date>
    </item>
  </channel>
</rss>

