- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-03-2017 10:11 AM
I'm looking to submit a FQDN block where I don't ever block the IP.
I've reviewed this article on blocking FQDN's but can't seem to figure out how to ignore the IP. We assign fake ip addresses to known malicius sites, and need the HTTP, HTTPS, SSH, etc traffic to route back to us, but the block on the FQDN is also blocking the IP once the lookup is processed.
Any suggestions?
Thanks.
04-27-2017 02:14 PM - edited 05-10-2017 10:24 AM
Check dns-req-section in page 19 of this document:
Creating Custom Application and Threat Signatures
There's an example for FQDN www.thebayareagamers.com
You can also add an EDL of type "Domain" and point it to a web-server that contains the list of domains you want to block.
See: https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/PANOS71Articles/article-id/10
03-06-2017 12:57 PM
I'm not sure I understand your problem. You mean you have a blocking rule with the FQDN as the destination address? If you want to reroute the traffic to some identified malicious websites, why do you have a blocking rule in the first place?
Benjamin
03-07-2017 01:22 PM
great question. We offer a service to a customer that blocks on a paloAlto system at their end, which we're fine with them blocking the FQDN, but we need to not block the IP at the same time to allow other traffic to make it through if the name/domain isn't blocked on the customer side.
Thanks.
04-27-2017 02:14 PM - edited 05-10-2017 10:24 AM
Check dns-req-section in page 19 of this document:
Creating Custom Application and Threat Signatures
There's an example for FQDN www.thebayareagamers.com
You can also add an EDL of type "Domain" and point it to a web-server that contains the list of domains you want to block.
See: https://live.paloaltonetworks.com/t5/tkb/articleprintpage/tkb-id/PANOS71Articles/article-id/10
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!