<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Minemeld to do FQDN refresh for security rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251716#M97041</link>
    <description>&lt;P&gt;Going to try this today but it looks like it will work perfectly! Thanks I will report back!&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2019 12:52:53 GMT</pubDate>
    <dc:creator>david.sherrill</dc:creator>
    <dc:date>2019-02-28T12:52:53Z</dc:date>
    <item>
      <title>Using Minemeld to do FQDN refresh for security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251390#M97038</link>
      <description>&lt;P&gt;So we recently started having trouble with our Palo's saying that the FQDN refresh job finished sucessfully but the items still TTL out and die. While waiting for support to look into it it occurs to me that I might beable to feed Minemeld a list of URL's and have it do the resolution and pump the results back to PAN. Anyone have any experience with this?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 16:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251390#M97038</guid>
      <dc:creator>david.sherrill</dc:creator>
      <dc:date>2019-02-26T16:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld to do FQDN refresh for security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251415#M97039</link>
      <description>&lt;P&gt;Can't help with the question, but I can say we've been having loads of issues with FQDN refreshes on our firewalls recently.&amp;nbsp; Don't know why its started to get worse (or if its just perception) but we have multiple open tickets in this space...!&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 18:44:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251415#M97039</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2019-02-26T18:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld to do FQDN refresh for security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251656#M97040</link>
      <description>&lt;P&gt;You could use Google DNS JSON API to do it:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;click on the AWS.AMAZON prototype&lt;/LI&gt;
&lt;LI&gt;click on &lt;STRONG&gt;NEW&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Paste the following in the prototype section (changed the hostname to be resolved :-))&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;{
   "age_out": {
      "default": null,
      "interval": 257,
      "sudden_death": true
   },
   "attributes": {
      "confidence": 100,
      "share_level": "green",
      "type": "IPv4"
   },
   "extractor": "Answer[?type==`1`].data.{indicator: @}",
   "indicator": "indicator",
   "prefix": "dns",
   "source_name": "dns.PaloAltoNetworks",
   "url": "https://dns.google.com/resolve?name=www.paloaltonetworks.com"
}&lt;/PRE&gt;</description>
      <pubDate>Thu, 28 Feb 2019 08:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251656#M97040</guid>
      <dc:creator>lmori</dc:creator>
      <dc:date>2019-02-28T08:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld to do FQDN refresh for security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251716#M97041</link>
      <description>&lt;P&gt;Going to try this today but it looks like it will work perfectly! Thanks I will report back!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 12:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251716#M97041</guid>
      <dc:creator>david.sherrill</dc:creator>
      <dc:date>2019-02-28T12:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld to do FQDN refresh for security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251737#M97042</link>
      <description>&lt;P&gt;It definatly works as expected, one question though is there an easy way to add new entries, or am I basically making a new one everytime I need to add a new URL?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 13:33:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251737#M97042</guid>
      <dc:creator>david.sherrill</dc:creator>
      <dc:date>2019-02-28T13:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using Minemeld to do FQDN refresh for security rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251740#M97043</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45186"&gt;@david.sherrill&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes. I'm afraid you need a new node (miner) per FQDN (details in the Google DNS API specification at &lt;A href="https://developers.google.com/speed/public-dns/docs/dns-over-https" target="_self"&gt;https://developers.google.com/speed/public-dns/docs/dns-over-https&lt;/A&gt;)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;If you're planning to configure 10's or more of them then you might want to take a look to the &lt;A href="https://github.com/PaloAltoNetworks/fqdn-service" target="_blank"&gt;FQDN-Service project&amp;nbsp;&lt;/A&gt;(AWS Serverless Component you can deploy at almost no montly cost and that can resolve 100's of FQDN's at once)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Xavi&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 13:41:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-minemeld-to-do-fqdn-refresh-for-security-rules/m-p/251740#M97043</guid>
      <dc:creator>xhoms</dc:creator>
      <dc:date>2019-02-28T13:41:54Z</dc:date>
    </item>
  </channel>
</rss>

