<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Proxy listen to broadcast? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394790#M91190</link>
    <description>&lt;P&gt;Yes of course option 43&amp;nbsp; is the best way.&lt;/P&gt;&lt;P&gt;But unfortunately the accesspoint was reset with "clear config except static ip". So it kept static ip address and does not send DHCP-discover/request now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Mar 2021 16:32:55 GMT</pubDate>
    <dc:creator>ChrisCon</dc:creator>
    <dc:date>2021-03-29T16:32:55Z</dc:date>
    <item>
      <title>DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/393707#M91039</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;I have a cisco wlan accesspoint (at remote site), which lost connection to central wlan-controller. Due to a mistake this ap still has static ip-address, so it does not send DHCP-discover/requests when it is started. But it sends DNS-requests searching for "cisco-capwap-controller". So I thought it might help to configure a DNS-proxy on the Palo Alto with static DNS entry "cisco-capwap-controller". Unfortunately the cisco ap sends its DNS-requests to broadcast-address 255.255.255.255. And this is dropped, even when firewall-rule with destination any (allowed) is used.&lt;BR /&gt;Is there a change to force Palo Alto to reply to the DNS-requests?&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 06:15:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/393707#M91039</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-03-25T06:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/393724#M91042</link>
      <description>&lt;P&gt;You may test with static arp entries like the examples below but they use network directed broadcast and not 255.255.255.255 so just test if it will work as I haven't done this myself with 255.255.255.255:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boLYCAY&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boLYCAY&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clq3CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clq3CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Cisco Access points also use DHCP and the option 43 for controller discovery, so maybe it is better to set the Palo Alto as the DHCP server or DHCP Relay (it is supported) than using DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/dhcp/dhcp-options/dhcp-options-43-55-and-60-and-other-customized-options.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/dhcp/dhcp-options/dhcp-options-43-55-and-60-and-other-customized-options.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 07:13:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/393724#M91042</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-25T07:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/393872#M91056</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176411"&gt;@ChrisCon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I would recommend just setting up DHCP option 43 for the access points on these remote offices like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;already mentioned. That's the actual process Cisco is expecting you to use in these type of scenarios.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:20:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/393872#M91056</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-03-25T14:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394483#M91147</link>
      <description>&lt;P&gt;Please test and tell us the results and mark the Discussion as closed if you managed to resolve it.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 19:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394483#M91147</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-26T19:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394789#M91189</link>
      <description>&lt;P&gt;Thanks for reply, but it did not help in my case.&lt;BR /&gt;But static arp was a good hint for future.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 16:29:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394789#M91189</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-03-29T16:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394790#M91190</link>
      <description>&lt;P&gt;Yes of course option 43&amp;nbsp; is the best way.&lt;/P&gt;&lt;P&gt;But unfortunately the accesspoint was reset with "clear config except static ip". So it kept static ip address and does not send DHCP-discover/request now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 16:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394790#M91190</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-03-29T16:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394941#M91208</link>
      <description>&lt;P&gt;Except if the static arp does not help to use a vWire if possible I think maybe somone must go and again clear the config but this time without "except static ip". Share how you solved this problem after this, if possible.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 14:14:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/394941#M91208</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-30T14:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Proxy listen to broadcast?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/395583#M91292</link>
      <description>&lt;P&gt;Another problem was, that the AP could not be located at the remote site.&lt;BR /&gt;But I could solve it with a nice little tool "AbateDNS". This replies to DNS-requests with a configured ip address. It even replies to broadcast-DNS. I only had to move a pc into the AP-VLAN. Then started the tool. The DNS-request-broadcast from Cisco-AP asking for "CISCO-CAPWAP-CONTROLLER" was seen and it replied with the configured ip address (WLC ip address).&lt;BR /&gt;Then AP knew the WLC and joined it. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20210401_abatedns_capwap1.jpg" style="width: 661px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30702i5FA903F7AD6BC488/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="20210401_abatedns_capwap1.jpg" alt="20210401_abatedns_capwap1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 11:57:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-listen-to-broadcast/m-p/395583#M91292</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-04-02T11:57:06Z</dc:date>
    </item>
  </channel>
</rss>

