Firewalls is not resolving domain names in address groups

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Firewalls is not resolving domain names in address groups

L1 Bithead

For some odd reason the firewall is not resolving external fqdn's that are part of an Address groups..

2 REPLIES 2

L3 Networker

Hi @LimaSupport 

 

Can you describe how do you confirm the firewall is unable to resolve the domains? Have you checked it from the GUI or CLI of firewall? 

Mostly, the reason for the firewall not able to resolve the FQDNs is due to the firewall unable to reach the DNS server.

By default, mgmt interface is used to connect to the DNS server (but can be changed from Device > Setup > Services > Service Route Configuration)

You can check if the DNS server is reachable. The CLI command below can then be used to view the list of FQDN objects and the IP addresses associated with that name.

  • PAN-OS 8.1 and below: > request system fqdn show
  • PAN-OS 9.1 and above: > show dns-proxy fqdn all

Alternatively, you can also check the FQDN resolution on the GUI by navigating to Address Objects > Select the FQDN Address Object in question > Click on 'resolve'.

Please go through the below KBs, which can be of help:

How to Configure and Test FQDN Objects
DNSPROXY and FQDN address refresh behaviours - PANOS 9.0 and Above

 

Regards,

L3 Networker

Have you also tried/checked if the DNS server (also configured on firewall) is able to resolve the external domains?

 

Regards,

  • 3923 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!