<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue With DNS Suffix in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394284#M91093</link>
    <description>&lt;P&gt;In GUI and system log is it written why the commit fails? In the CLI also check the managment plane ms.log and devsrv.log.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 12:13:43 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-03-26T12:13:43Z</dc:date>
    <item>
      <title>Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394261#M91090</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The challenge was that we need to do commit with wildcard in dns suffix ie. *.&lt;A href="https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fxyz.com&amp;amp;c=E,1,M-91GO_HAGgCmVA8ahXi83TAoV3XAy3B7Z1GFg4x6ls_SRwYKQma1JtP2l5OSfoky5vgUeLITqdMDksGtvLUIWOOor1GaAXkANfXF2IiQm1-nFgo3t3J&amp;amp;typo=1&amp;amp;ancr_add=1" target="_blank"&gt;xyz.com&lt;/A&gt; but it failed ( PAN OS 9.1.7).&lt;/P&gt;&lt;P&gt;For workaround we have removed wildcard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You seen in other firewall with panos 9.1.5 its having dns suffix with wildcard. For resolving dns suffix issue with wildcard,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading to panos from 9.1.5 to 9.1.7 why wildcard not taking in dns suffix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthikeyan Balamurugan&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 11:20:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394261#M91090</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T11:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394284#M91093</link>
      <description>&lt;P&gt;In GUI and system log is it written why the commit fails? In the CLI also check the managment plane ms.log and devsrv.log.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394284#M91093</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T12:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394292#M91095</link>
      <description>&lt;P&gt;where exactly are you adding the wildcard suffix?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:24:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394292#M91095</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T12:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394297#M91096</link>
      <description>&lt;P&gt;We have added *(Star Symbol) i.e *.abc.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in 9.1.5 its working ie *.abc.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in 9.1.7 *.abc.com is not working so we have changed to abc.com and we commit the changes then its works&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394297#M91096</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T12:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394298#M91097</link>
      <description>&lt;P&gt;After removing * symbol its works&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:29:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394298#M91097</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T12:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394301#M91100</link>
      <description>&lt;P&gt;This is&amp;nbsp; we actually configured&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Exclude Access Routes      :     
	DNS Servers                :      172.25.225.15
	DNS Suffix                 :     *.ibm.com abc.com xyz.com 123.com 
	config name                :  GW_Twitter_WFH
	User Groups                :     cn=palo_ssl_vpn_twitter,ou=groups,ou=special,ou=gps_bangalore_mtp,&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:38:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394301#M91100</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T12:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394323#M91103</link>
      <description>&lt;P&gt;are you adding this to a GP gateway\agent\network services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you post the cli command that you are using for this. or is it done via GUI.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394323#M91103</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T13:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394329#M91106</link>
      <description>&lt;P&gt;yup, the configuration done by GUI only&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:22:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394329#M91106</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T13:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394331#M91107</link>
      <description>&lt;P&gt;OK but where in the GUI&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:23:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394331#M91107</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T13:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394335#M91108</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="suffix issue.png" style="width: 984px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30597iCCDFA4D90CB952B1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="suffix issue.png" alt="suffix issue.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IBM Wildcard Issue.JPG" style="width: 468px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30598i951BA58706BDA85B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IBM Wildcard Issue.JPG" alt="IBM Wildcard Issue.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394335#M91108</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T13:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394340#M91109</link>
      <description>&lt;P&gt;OK thanks for the information.&lt;/P&gt;&lt;P&gt;I cant work out why you would ever need a wildcard in a dns search suffix.&lt;/P&gt;&lt;P&gt;how does that even work?????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you add suffix "abc.com" and ping "fred" then your dns server will try to resolve "fred.abc.com".&lt;/P&gt;&lt;P&gt;if you add suffix&amp;nbsp; "*.abc.com" and ping "fred" are you expecting the dns to resolve to "fred.(any name).abc.com"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i don't think this has ever worked as expected and perhaps earlier versions just ignored the error and the later versions now error check this field.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394340#M91109</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T13:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394342#M91110</link>
      <description>&lt;P&gt;I can't even add that to my gateway config without an error...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1616766852437.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30599iEDEC469F4C7948ED/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1616766852437.jpeg" alt="MickBall_0-1616766852437.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:54:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394342#M91110</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T13:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394344#M91112</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;In the Palo Alto documentation it should work as they give examples with &lt;SPAN class="ph cmd"&gt;&lt;SPAN class="ph userinput"&gt;*.target.com&lt;/SPAN&gt;&lt;/SPAN&gt; or * .gmail.com. Try adding only the DNS suffix *.ibm.com without any others as test and then contact the Palo Alto TAC as it seems as a bug. I have seen an issue bug where this wildcard suffix needs to be the last domain in the list, this is why I suggest testing this before the tac case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also this optimized split tunneling was added inm 8.1 version and again they give examples with *.&amp;lt;domain-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/globalprotect-features/split-tunnel-for-public-applications.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/globalprotect-features/split-tunnel-for-public-applications.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also double check your globalprotect license just in case as this option is inluded with it not with the normal license. I don't think this is the issue but just in case.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 26 Mar 2021 14:03:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394344#M91112</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T14:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394347#M91114</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are referring to split tunnel domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the setting that is having issues is the DNS search suffix here... Network Services&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1616767394167.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30600iBAEE61FBE196DA97/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1616767394167.jpeg" alt="MickBall_0-1616767394167.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 14:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394347#M91114</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T14:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394353#M91117</link>
      <description>&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981" target="_self"&gt;&lt;SPAN class=""&gt;MickBall&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yes we hav facing the issue here on network services&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 14:50:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394353#M91117</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T14:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394354#M91118</link>
      <description>&lt;P&gt;I don't think a wildcard in network services has ever worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what do you expect to gain from this wildcard.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 14:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394354#M91118</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T14:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394355#M91119</link>
      <description>&lt;P&gt;No it was totally customer expectation .&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 14:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394355#M91119</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2021-03-26T14:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issue With DNS Suffix</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394356#M91120</link>
      <description>&lt;P&gt;OK so ask the customer what they expect to achieve by having a wildcard in a DNS search suffix.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 15:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-dns-suffix/m-p/394356#M91120</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-26T15:02:49Z</dc:date>
    </item>
  </channel>
</rss>

