Custom DNS name

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Custom DNS name

L4 Transporter

We have a DNS name genieo that is not being recognized and is not included in the signatures. Two things first is there a way to identify it with a custome signature with the object/anti-spyware  and then be able to send it to a sinkhole?

10 REPLIES 10

Cyber Elite
Cyber Elite

You could:

- use custom URL category and block this traffic

- use DNS Proxy and fake some random (localhost) ip as answer

- if running 7.1 use Dynamic Lists with type URL to create custom url categories and block in the policy

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Do you have to have the URL filtering subscription to do these two?

 

- use custom url category and block this traffic

- if running 7.1 use the Dynamic Lists with the URL to create custom url categories and block the policy

No

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Good I will check it out

I don't see options to sinkhole these only to block etc. My manager wants to be able to sinkhole.

jprovine,

If you look at the following I'm fairly certain that you can accomplish this fairly easily with anti-spyware filtering.

Good suggestion but I tried that but I didn't see a way to sinkhole it only to block or reset just the basic but no sinkhole option than I can find, if you want give me the instruction maybe I missing it

Good suggestion but I tried that and I didn't see a way to sinkhole it, only to block or reset just the basic but no sinkhole option than I can find, if you want give me the instruction maybe I missing it

You have to run 7.1 to include your custom url lists into sinkhole.

With 7.0 or below you have to use DNS Proxy and use this to send back fake DNS replies back.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Good information I am currently on 6.1.11 so that is not a option for me at this point

  • 4019 Views
  • 10 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!