DNS rewrite for DNS reply packet is not working.

DNS rewrite for DNS reply packet is not working.

10572
Created On 02/15/22 03:30 AM - Last Modified 06/03/23 08:35 AM


Symptom




Environment


  • Palo Alto Firewalls
  • PAN-OS 9.1, 10.1, 10.2
  • Destination NAT rule configured with DNS rewrite
  • Disable Server Response Inspection (DSRI) checked.


Cause


  • One of the reasons DNS rewrite operation can fail is due to "Disable Server Response Inspection'' option enabled/checked in the security policy.
  • With "Disable Server Response Inspection '' enabled/checked Firewall stops Layer 7 inspection for response traffic(Server to Client Traffic) and it will stop DNS rewrite operation on DNS response packets.
  • Refer to Disable Server Response Inspection BPA Checks for details.

 


Resolution


  1. Disable/Uncheck "Disable Server Response Inspection" in the security policy (GUI: Policies > Security > (select the rule). Note that DSRI his is disabled by default.
  2. Commit the configuration.

 

Sec_Policy_SS-2.PNG


 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NDqCAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language