DNS Proxy stops responding to requests

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

DNS Proxy stops responding to requests

L6 Presenter

Has anyone else recently experienced problems with DNS Proxy stopping responding to client DNS requests?

 

I run DNS Proxy on multiple sub-networks, such as our public Wifi zone, along with spyware/URL filtering for preventing access to malware/prohibited/etc. domains. The Security Policies prevent access to proxy avoidance and encrypted DNS. For the last week I have continually run into a problem were the public Wifi DNS Proxy stops responding to nearly all client DNS requests. Stopping/starting the the DNS Proxy temporarily restores service, but it fails again within a couple minutes to hours. Changing DNS cache settings has made no difference.

 

Under DNS Proxy statistics, "Queries forwarded to servers" is outnumbering "Queries received from servers" by 5-10 to 1. The DNS Proxy seems to start failing when "Pending UDP" connections climbs to around 2000 open queries.

 

It appears that these open DNS queries are being blocked in the security rules as proxy/encrypted DNS (expected) for "mask.icloud.com" (and other Apple-related FQDNs). It further appears that Apple changed their base config about a week ago to enable "iCloud Private Relay" by default, which has caused Apple devices to change from doing DNS requests for "mask.apple-dns.net" (which returns an A record) to DNS requests to "mask.icloud.net" (which returns a C record to mask.apple-dns.net). And the Apple devices are doing far more of these requests when blocked. It seems the combination of the C name and the increase in blocked requests is causing the DNS Proxy to hang and stop processing additional DNS queries.

 

I have been able to temporarily relieve the DNS Proxy hangs by inserting a "mask.icloud.com - 127.0.0.1" static DNS entry, but all the Apple devices can no longer access the internet unless the disable "iCloud Private Relay". Has anyone else experienced this? Any other options for bypassing while maintaining Security Policies?

 

1 REPLY 1

L6 Presenter

After digging through days of logging and generating stats, it appear this Apple change took place between about 8/17 1900-2100 UTC (1200-1400 local time). Previously, the queries for mask.apple-dns.net were generating about 20,000-60,000 DNS blocks per hour. After the change to icloud.com DNS, the PA is blocking about 140,000-220,000 DNS requests per hour (from roughly 50 or so Apple devices on Wifi). Almost no DNS requests for apple-dns.net FQDNs remain.

 

Following @phampx's suggestion, I changed the DNS Proxy static entries for "mask.icloud.com", "mask-api.icloud.com", and "mask-h2.icloud.com" to a static entry of "0.0.0.0". This seems to make a test Apple device immediately signal that iCloud Private Relay is not available on the network. There are still a huge number of DNS requests constantly blocked, but the Pending UDP connections is back down in the range of 40-300, instead of 2000+.

https://live.paloaltonetworks.com/t5/general-topics/what-is-the-best-practice-to-block-icloud-relay/...

 

  • 42 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!