DNS issue due to Proxy-Avoidance-and-Anonymizers software

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

DNS issue due to Proxy-Avoidance-and-Anonymizers software

L0 Member

Hello All,

We observered a Sev 1 issue last week which was related to internet slowness that impacted large number of users . During the issue start time , we observed DNS traffic blocks between our DNS server and URL services.disconnect.me ( Palo Alto firewall was flagging it as Threat)

Regarding this URL – this is related to a browser extension "disconnect me" which is not malicious , this is used to avoid tracking on the internet.

URL: services.disconnect.me

Categories: Proxy-Avoidance-and-Anonymizers

Risk Level: Low-Risk

   

my setup isclient -> internal dns server -> dnsproxy(PAN firewall) -> external dns server

 

Though, the issue was fixed after removing DNS security from my antispyware profile which was called into the DNS rule.

 

I'm trying to understand if this URL/extension or similar Ad blocking/Anti-tracking extension can impact/corrupt the DNS traffic which can eventually choke the network.

0 REPLIES 0
  • 1715 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!