Does firewall block the traffic destined to the real IP of the sinkhole domain if a client uses the IP and not querying the domain?
134
Created On 03/04/22 17:24 PM - Last Modified 07/30/26 00:44 AM
Question
Does firewall block the traffic destined to the real IP of the sinkhole domain if a client uses the IP and not querying the domain?
Answer
The sinkhole ip address is provided for dns query to malicious domain to hide the real IP address if an action is set 'sinkhole'. Palo Alto built-in EDLs work independently. The EDLs have the lists of IPs which initiate malicious traffic normally.
If the real IP of the sinkhole domain is included in the EDLs then the action of the traffic to and from the real IP is taken based on the matching security policy where EDLs are used.
If the real IP of the sinkhole domain is NOT included in the EDLs then the action of the traffic to and from the real IP is taken based on the matching security policy where EDLs are not used.