we have some problems in managing policy rules for Lifesize videoconference devices. With their new cloud architecture they provided a document ( https://community.lifesize.com/docs/DOC-4512) with an FQDN and port list to open. The problem is that some url int the list ( fwc.lifesizecloud.com, fwa.lifesizecloud.com...) can be resolved with hundred or more IP and Palo Alto reads and cache for every FQDN only the first 32 ip resolved and sended from DNS server. So FQDN based policy works intermittently. Moreover with this type of traffic it`s non simple to configure application based policy and url category filter does not seems to work correctly . Is there a simple way with Minemeld to obtain an usable ip list from an FQDN list as INPUT node?
Have you already had experience with the new Lifesize architecture?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!