DNS Proxy Encounters Error in Processing Packet

DNS Proxy Encounters Error in Processing Packet

26709
Created On 09/26/18 19:16 PM - Last Modified 06/13/23 03:08 AM


Resolution


Symptom

The DNS proxy is not working with the following errors viewed in the dnsproxyd.logs:

Jun 25 12:35:21 Error:pan_dnsproxyd_recv_server_udp_cb(pan_dnsproxy_udp.c:487): 
[Drop Rcvd ServerPkt]: Error in processing packet
Jun 25 12:35:21 Error:pan_dnsproxy_process_server_pkt(pan_dnsproxy_pkt.c:1320):
[4552/-][Drop RcvdServer Pkt]: No pending entry in conn tbl for server_tid:4552
Jun 25 12:35:21 Error:remove_conn_tbl_entry(pan_dnsproxy_pkt.c:284):conn_tbl[4552]
entry is already freed!

 

The DNS proxy statistics shows a greater amount of queries forwarded to the DNS servers and less responses received from the DNS servers:

> show dns-proxy statistics all
Name: L1-DNS_PROXY
Interfaces: ethernet1/4 ethernet1/6 ethernet1/8
Counters:
  Queries received from hosts:1121308
  Responses returned to hosts:1071528
  Queries forwarded to servers:449253
  Responses received from servers:399473
  Queries pending:0
  TCP:0
  UDP:0

 

Causes

  1. The symptoms occur if there is an excessive delay of the DNS server response, as the connection entries have been cleared from the tables, due to the amount of time it took the server to respond.
  2. Another possible cause of this issue, not having a Security Policy to allow outbound DNS for the Proxy Server, or the outbound traffic is missing the NAT rule. The DNS Proxy traffic was being dropped and timing out.

 

owner: nayubi

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm42CAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language