FQDN not resolved

Reply
Hub
L0 Member

FQDN not resolved

Hi

On a Palo Alto Firewall, we created an address object using FQDN Type.

We use this object as a destination address in the security rule « TEST-FQDN-1 »

But checking the security policy (show running security-policy) we can see the destination is not resolved  (destination 0.0.0.0;)

TEST-FQDN-1 {

        from any;

        source any;

        source-region any;

        to Trust;

        destination 0.0.0.0;

        destination-region any;

        user any;

        application/service any/any/any/any;

      action allow;

}


And checking the fqdn entries (system fqdn show) we can see the FQDN is in a « Not Resolved » status.

We tried to ping the host from the firewall and the ping well resolve the address so it looks like the DNS configuration is OK

We also tried to refresh FQDN entries (request system fqdn refresh) but it doesn’t change anything.

Do we miss something ? Do we have to add some more configuration ?

Please help

Thank you

Hubert

Hub
L0 Member

Re: FQDN not resolved

Problème résolu

Not applicable

Re: FQDN not resolved

Hi There,

Are you able to share the resolution to this issue?

L0 Member

Re: FQDN not resolved

You should post the resolution so everyone benefits.

Not applicable

Re: FQDN not resolved

I managed to work this out....

We were using UPPERCASE FQDN objects, changed them to lowercase and all is good :smileyhappy:

L0 Member

Re: FQDN not resolved

I see.

Palo Alto Networks Guru

Re: FQDN not resolved

Which software version were you using?  Was the object name capitalized, or the actual FQDN address?

Hub
L0 Member

Re: FQDN not resolved

Hi everybody,

The Palo Alto has some problem to resolve object name in uppercase.

Palo Alto confirmed that they will fix this bug in version 4.0.5.

Until, you may use lowercase object name and it will work.

Hubert

Palo Alto Networks Guru

Re: FQDN not resolved

This is a known issue that will be solved in 4.0.5.  The issue is not the object name, it is the the URL itself that cannot be capitalized.

Highlighted
KGC
L3 Networker

Re: FQDN not resolved

We are having this exact same issue, only on 4.1.12 and using lower-case. (Perhaps I should have created a new thread for this given that the original post is now two years old, but Hub described it so well I didn't see a reason to duplicate the effort :smileywink:)

The problem is only affecting a single address object, and in the FDQN logs it shows as "not resolved". Other similar entries are resolving correctly. What's odd is that this was working when originally configured some weeks ago. The firewall is able to ping the address by name, so name resolution is working. The problem entry is outlook.office365.com which is a mix of both IPv6 and IPv4 addresses.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!