How Palo Alto enabled with DNS Sinkhole will see original Client IP Address; when internal DNS server working in Recurisive mode?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How Palo Alto enabled with DNS Sinkhole will see original Client IP Address; when internal DNS server working in Recurisive mode?

L0 Member

Hi All,

 

I need help in solution to know how actually Palo Alto enabled with DNS Sinkhole will see original client IP Address making DNS request to a domain in DNS sinkhole list.

 

More Information is:

My client computer with IP address (10.10.10.10) configured with Internal DNS server with IP Address (10.10.10.20). Internal DNS server working in the recursive mode so if it does not have DNS answer; it will send DNS queries to TLDs to get an answer.

 

For both my client computer and internal DNS server, Gateway is Palo Alto Next-Generation Firewall with Gateway address 10.10.10.1

I have enabled DNS Sinkhole to domain query lets say example.com to 10.10.10.254.

Now in this setup how my Palo Alto firewall will identify who was original client requested for example.com because we know DNS server will send DNS request with its own source IP address to the Internet and not with original Client IP Address.

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Sinkhole will 'poison' the DNS reply.

 

so usually the client sends a dns request to the internal dns, the internal dns then requests the information from the TLD, the tld replies with an IP address  for the A/AAAA record, and the Palo Alto will then replace the IP with the sinkhole IP

 

the internal DNS relays the poisoned answer to the client and the client then tries to connect to the sinkhole IP, this is how you know the client was the original requestor

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Sinkhole will 'poison' the DNS reply.

 

so usually the client sends a dns request to the internal dns, the internal dns then requests the information from the TLD, the tld replies with an IP address  for the A/AAAA record, and the Palo Alto will then replace the IP with the sinkhole IP

 

the internal DNS relays the poisoned answer to the client and the client then tries to connect to the sinkhole IP, this is how you know the client was the original requestor

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 1848 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!