Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

DNS Servers - can you set 3?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

DNS Servers - can you set 3?

L4 Transporter

As subject, the GUI lets you set two, ideally we want to set 3 as we have one at a remote site.

1 accepted solution

Accepted Solutions

L7 Applicator

Sorry, only two from the cli as well.

# set deviceconfig system dns-setting servers

+ primary     Primary DNS server IP address

+ secondary   Secondary DNS server IP address

  <Enter>     Finish input

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

View solution in original post

6 REPLIES 6

L7 Applicator

Sorry, only two from the cli as well.

# set deviceconfig system dns-setting servers

+ primary     Primary DNS server IP address

+ secondary   Secondary DNS server IP address

  <Enter>     Finish input

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L5 Sessionator

Hello networkadmin,

Currently there is a limitation on the firewall to configure only two DNS servers. However, I see a feature request (FR ID : 2569) submitted to our content development team for the PAN to have the capability to add Tertiary and Quaternary DNS servers as well. You can request your account's sales engineer to vote for it so that we can include it in our future software releases as soon as possible

Hope that helps!

Thanks and regards,

Kunal Adak

Damn Smiley Happy

Feature request?  (sorry never sure who actually works for Palo Alto as you guys don't identify yourselves with a logo or anything Smiley Happy)

I'm an end-user in the enterprise space.

Feature Requests are an internal Palo Alto database of new features users have requested from sales engineering.  You can ask your sales team to add your company as a "vote" for the new feature.

I''m told that if a lot of users vote for a feature they move it up on the development timeline.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L0 Member

Any updates on this?

Cyber Elite
Cyber Elite

Hello @dmburgess

 

although I can't provide an update on status of that feature request, I think you can use one of below alternative approaches to overcome 2 IP address limitation. Either use a load balancer to point DNS requests to or use Anycast IP for DNS servers.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 3614 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!