- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-09-2018 03:54 AM
Hi to all
I have a problems with riles with FQDN
For example i created rule:
source ip - destination ip - destination port
I changed ip to FQDN object - pc1.domain.com. Palo Alto can resolve name to IP.
New Rule:
source FGDN - destination ip - destination port.
In first five minutes (more or less) rule works fine, but after that traffic not hitting this rule
Sometimes i see hit in traffic log, but most times traffic pass this rule and hit default rule.
FQDN record is present, but sometimes TTL is negative. FQDN refresh time is 1800 sec (default)
request system fqdn show
FQDN Table : Last Request time Fri Nov 9 11:30:36 2018
--------------------------------------------------------------------------------
IP Address Remaining TTL Secs Since Refreshed
pc1.domain.com (Objectname pc1.domain.com):
192.168.100.5 968 232
pc1.domain.com (Objectname pc1.domain.com):
192.168.100.5 -305 1505
pc1.domain.com (Objectname pc1.domain.com):
192.168.100.5 -514 1714
request system fqdn show
Server error : A refresh is in progress. Please try again later.
pc1.domain.com (Objectname pc1.domain.com):
192.168.100.5 1099 101
What is wrong?
11-09-2018 07:57 AM
I would assume that the TTL set on your local DNS server is less than the default FQDN refresh time, and that you might have to decrease this to less than your set TTL on the DNS server.
11-11-2018 09:17 PM
Thanks for the answer. Can you tell me how to check TTL on the DNS server so that I can compare it with PA FQDN refresh time?
11-12-2018 07:51 AM
Assuming Microsoft Servers are being used to supply DNS.
Open DNS manager, click view --> advanced.
When you open a DNS record, there will be a new field for TTL which reveals the set TTL value.
11-12-2018 10:16 PM
My colleagues reported that TTL on the DNS server is 1 minute for local records.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!