Palo Dual Action on Same Malicious Domain

cancel
Showing results for 
Search instead for 
Did you mean: 

Palo Dual Action on Same Malicious Domain

L4 Transporter

We have found in the logs, Malicious DNS queries are being blocked but few of them are in Alert State. however the Domain is marked as a malicious in DNS signature at Threat Vault.

Can you please elaborate why paloalto having dual action on same malicious domain.

 

 

Joshan_Lakhani_0-1610996825658.png

 

3 REPLIES 3

Cyber Elite
Cyber Elite

do you happen to have multiple vsys or could these 'alert' ones be hitting a different rule altogether ?

 

Tom Piens
PANgurus

@reaper we are not using Vsys moreover it's  hit on same policy. Furthermore when we check the other domains we are still see that some time paloalto it's show alert and 90% is sinkhole please suggest. 

@reaper @BPry @MP 

 

In our case, if the get the IP address of the malicious domain and it generates the “alert” on the firewall.

 

Joshan_Lakhani_0-1611346021358.png

 

 

Joshan_Lakhani_1-1611346021362.png

 

One the second time it will identify its malicious domain then the query will send to the sinkhole.

 

Joshan_Lakhani_2-1611346035015.png

 

 

Joshan_Lakhani_3-1611346035018.png

 

DNS sinkhole can be used to identify infected hosts on a network where there is an internal DNS Server in-route to the firewall that causes the reference of the original source IP address of the host that first originated the query to be lost (the query is received by the Internal DNS Server, and the internal DNS Server sources a new query if the name-to-IP resolution is not locally cached).

 

 

The things we have understood by your assistance but we could not found any document having the same use case or actual flow of DNS or its cache how they works.

Can  you please suggest any document or use case.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!