FQDN list doesnt work

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

FQDN list doesnt work

L0 Member

Hey all,

 

I created a simple FQDN allow list and added google.com.  When I ping or curl google.com it only works sometimes.  Any ideas?

1 REPLY 1

L3 Networker

Hello @SCalvanese,

I saw your post and have a few recommendations for you. You may want to look at it initially,

 

The maximum number of address objects you can resolve for an FQDN is increased from 10 of each address type (IPv4 and IPv6) to a maximum of 32 each. However, the combination of IPv4 and IPv6 addresses cannot exceed 512B; if it does, addresses that are not included in the first 512B are dropped and not resolved.

 

FQDN can also be helpful to control other services that don’t relate to web browsing like FTP, ssh, or any other service.

 

As a workaround, it is possible to configure the rule with  App-id [google-base] or by using a custom URL {google.com}, instead of using FQDN Object


 Thanks and Regards,


Edison K Benny
Product Specialist
Palo Alto Networks
https://live.paloaltonetworks.com/t5/cloud-ngfw-discussions/bd-p/Cloud_NGFW_Discussions
*Don’t forget to accept the solution provided!

 

 

 

  • 1737 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!