Why does the Cloud default DNS Proxy IP does not respond for DNS request in Prisma Access Remote Networks

Why does the Cloud default DNS Proxy IP does not respond for DNS request in Prisma Access Remote Networks

1744
Created On 01/23/24 02:33 AM - Last Modified 02/07/25 03:54 AM


Question


Panorama Cloud Services > Status > Network details shows a Remote Network DNS proxy IP address as 10.1.189.254 in this example.
002.png

However, even when performing nslookup using this IP from the RN peer, the DNS response is not returned. Why?

> google.com
Server:  [10.1.189.254]
Address:  10.1.189.254

DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
*** Request to [10.1.189.254] timed-out


Environment


  • Prisma Access
  • Remote Networks
  • DNS


Answer


  1. In order to use the DNS Proxy on the RN SPNs, some configuration conditions need to be met.
  2. For example, the DNS Proxy in the RN SPN will not work in the scenario shown in the diagram
    • This is because the above configuration meets the pattern below.
      • INTERNAL DNS RESOLUTION METHOD = No configuration
      • EXTERNAL DNS RESOLUTION METHOD = Cloud Default
      • PRISMA ACCESS PROXIES THE DNS REQUEST (YES/NO) = No
    • If the configured pattern meets "PRISMA ACCESS PROXIES THE DNS REQUEST (YES/NO) = No", the RN SPN does not work as DNS Proxy.
    • Configure the DNS resolution method using the pattern that shows "PRISMA ACCESS PROXIES THE DNS REQUEST" = "Yes".

Note:If you enable ZTNA Connector, Prisma Access SPNs will proxy all DNS requests.
001.png

  1. Refer to the DNS Resolution for Mobile Users and Remote networks for more details. 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008WikCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail