Have 2 HA VMs with 9.0.1
In section 3), how does this need to be configured ((addr.dst in 10.15.0.20) ) when using Palo Alto Networks Sinkhole IP (sinkhole.paloaltonetworks.com) ?
The IP addresses currently are IPv4—sinkhole.paloaltonetworks.com and a loopback address IPv6 address—::1. These address are subject to change and can be updated with content updates.
As per my previous update, in PAN-OS v9.0.1:
Ahh ok got it. Is there a list of available sinkhole IPs that Palo Alto hosts? I am following along their guide "See Infected Hosts that Attempted to Connect to a Malicious Domain" and the report you create needs you to specify a specific IP destination, which has gone away in 9.0.
The panw hosted one is sinkhole.paloaltonetworks.com, by you can use any IP, preferably something that's not on the internet and not in your network either (unless you have a Honeypot)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The Live Community thanks you for your participation!