<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does DNS Sinkhole actually works? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394965#M91215</link>
    <description>&lt;P&gt;Just a quick reply.. if you want to learn more about DNS Sinkhole.. please check out the Learning Happy Hour that we have on the LIVEcommunity YouTube channel here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=FUFtEEMEE00&amp;amp;list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_&amp;amp;index=36&amp;amp;ab_channel=PaloAltoNetworksLIVEcommunity" target="_blank"&gt;https://www.youtube.com/watch?v=FUFtEEMEE00&amp;amp;list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_&amp;amp;index=36&amp;amp;ab_channel=PaloAltoNetworksLIVEcommunity&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you liked any of that, please be sure to check out the other Learning Happy Hours here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/playlist?list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_" target="_blank"&gt;https://www.youtube.com/playlist?list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Mar 2021 17:22:45 GMT</pubDate>
    <dc:creator>jdelio</dc:creator>
    <dc:date>2021-03-30T17:22:45Z</dc:date>
    <item>
      <title>How does DNS Sinkhole actually works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394864#M91198</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need your help to better undestand how DNS Sinkhole actually works.&lt;/P&gt;&lt;P&gt;I mean, i know how it works, how to configure it, but i'm facing a strange behaviour i cannot understand.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="dns sinkhole.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30648iCAA569198955C99F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="dns sinkhole.png" alt="dns sinkhole.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the photo i have uploaded i have an example.&lt;/P&gt;&lt;P&gt;Both source and destination are in the same subnet (i have obscured the first two octects for privacy)&lt;/P&gt;&lt;P&gt;the destination of the log (99.7) should be the client trying to contact the C2 domain, but the source doesn't exists! It's not the interface IP of PA, nor a host in the subnet!&lt;/P&gt;&lt;P&gt;this is not the only log showing this, there are many of them, and every one have this particularity: the source is always a previous or following IP (for example, if the destination IP is 99.100, i can find sources 99.99 or 99.101, and so on).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone who better knows this function heelp me understand what is happening?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 08:20:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394864#M91198</guid>
      <dc:creator>DKanta</dc:creator>
      <dc:date>2021-03-30T08:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: How does DNS Sinkhole actually works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394904#M91201</link>
      <description>&lt;P&gt;So you do not have LDNS server with an IP address as a source as if the clients are not directly connecting to the Palo Alto and using as a DNS proxy it could be a LDNS server &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/use-dns-queries-to-identify-infected-hosts-on-the-network/dns-sinkholing" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/use-dns-queries-to-identify-infected-hosts-on-the-network/dns-sinkholing&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usefull things how to check the DNS sinkhole:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clk2CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clk2CAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmFCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmFCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also is the source zone the same as the destination zone as if the IP addresses are in the same network they should be but maybe the source IP address is spoofed (false) or you have some kind of asimetric routing?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 18:49:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394904#M91201</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-30T18:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: How does DNS Sinkhole actually works?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394965#M91215</link>
      <description>&lt;P&gt;Just a quick reply.. if you want to learn more about DNS Sinkhole.. please check out the Learning Happy Hour that we have on the LIVEcommunity YouTube channel here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=FUFtEEMEE00&amp;amp;list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_&amp;amp;index=36&amp;amp;ab_channel=PaloAltoNetworksLIVEcommunity" target="_blank"&gt;https://www.youtube.com/watch?v=FUFtEEMEE00&amp;amp;list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_&amp;amp;index=36&amp;amp;ab_channel=PaloAltoNetworksLIVEcommunity&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you liked any of that, please be sure to check out the other Learning Happy Hours here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/playlist?list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_" target="_blank"&gt;https://www.youtube.com/playlist?list=PLD6FJ8WNiIqUCHEz5r8KDmFFtE37PlZT_&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 17:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-dns-sinkhole-actually-works/m-p/394965#M91215</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-30T17:22:45Z</dc:date>
    </item>
  </channel>
</rss>

