Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Allow listing Dynamic IP sites

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Allow listing Dynamic IP sites

L0 Member

Hi All,

 

We have an issue where we allow list a domain using a dynamic IP, but the host calling the domain and the firewall resolve to different addresses and the connection is drops (in most cases).

 

We have looked at URL categories but seem to face the same issue.

 

Can anyone suggest a solution?

2 REPLIES 2

Cyber Elite
Cyber Elite

Thank you for posting question @AWaring would it be possible to get an example of one of the domain?

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

@AWaring,

If you use a custom URL category to allow access to the domain and configure the entries properly you don't have to restrict the destination address. If you can give us a bit more information on how you have configured the security policy allowing access to the URL category we can help you get it configured correctly.

The following questions are only relevant if you are attempting to do this through an FQDN object. Again, if you are doing this with a URL category I wouldn't bother limiting it to destination addresses. 

  • How often do you have the firewall set to refresh FQDNs? What do you have the minimum refresh rate set to?
  • What version of PAN-OS are you running? Newer versions refresh based off of the records TTL.
  • Are the clients and the firewall setup to use the same DNS providers? 
  • 1948 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!