Issue With DNS Suffix
cancel
Showing results for 
Search instead for 
Did you mean: 

Issue With DNS Suffix

L3 Networker

Dear Team,

 

The challenge was that we need to do commit with wildcard in dns suffix ie. *.xyz.com but it failed ( PAN OS 9.1.7).

For workaround we have removed wildcard.

 

You seen in other firewall with panos 9.1.5 its having dns suffix with wildcard. For resolving dns suffix issue with wildcard, 

 

After upgrading to panos from 9.1.5 to 9.1.7 why wildcard not taking in dns suffix.

 

Regards

Karthikeyan Balamurugan

17 REPLIES 17

L4 Transporter

In GUI and system log is it written why the commit fails? In the CLI also check the managment plane ms.log and devsrv.log.

L7 Applicator

where exactly are you adding the wildcard suffix?

L3 Networker

We have added *(Star Symbol) i.e *.abc.com

 

in 9.1.5 its working ie *.abc.com

 

But in 9.1.7 *.abc.com is not working so we have changed to abc.com and we commit the changes then its works 

After removing * symbol its works

This is  we actually configured 

 

Exclude Access Routes      :     
	DNS Servers                :      172.25.225.15
	DNS Suffix                 :     *.ibm.com abc.com xyz.com 123.com 
	config name                :  GW_Twitter_WFH
	User Groups                :     cn=palo_ssl_vpn_twitter,ou=groups,ou=special,ou=gps_bangalore_mtp,

 

are you adding this to a GP gateway\agent\network services.

 

could you post the cli command that you are using for this. or is it done via GUI.

yup, the configuration done by GUI only

OK but where in the GUI

suffix issue.pngIBM Wildcard Issue.JPG

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!