Sie sind auf Seite 1von 5

How to Configure DNS Sinkholing on PAN-OS 6.

0 | Palo Alto Networks Live 3/24/15, 5:26 AM

All Places > Knowledge Base > Documents

How to Configure DNS Sinkholing on PAN-


OS 6.0 Version 8

created by rvanderveken on Nov 18, 2013 1:28 AM, last modified by panagent on Oct 1, 2014 5:22 PM

Overview
This document describes the steps to configure the DNS sinkhole action.

DNS sinkholing is an action, introduced in PAN-OS 6.0, that can be enabled in Anti-Spyware profiles. A DNS
sinkhole enables the Palo Alto Networks device to forge a response to a DNS query for a known malicious
domain, causing the malicious domain name to resolve to a definable IP address. This feature can be used to
identify infected hosts on the protected network using DNS trac in situations where the firewall cannot see the
infected client's DNS query (that is, the firewall cannot see the originator of the DNS query).

Steps
1. Make sure the latest Antivirus updates are installed on the Palo Alto Networks device.
2. Create a loopback interface (Network > Interfaces > Loopback) with the "sinkhole" IP address. The following
example uses the "loopback.10" interface:

3. Create an Anti-Spyware profile (Objects > Security Profiles > Anti-Spyware) where DNS sinkholing is
enabled, and specify the IP address of the loopback interface:

https://live.paloaltonetworks.com/docs/DOC-6220 Page 1 of 8
How to Configure DNS Sinkholing on PAN-OS 6.0 | Palo Alto Networks Live 3/24/15, 5:26 AM

4. Apply the Anti-Spyware profile on the security policy that allows DNS trac from the internal network (or
internal DNS server) to the internet:

5. Commit the configuration.

Verify that the sinkholing is working as expected using a network protocol analyzer. For example, with the use of
WireShark:
1. Initiate a ping to a malicious domain (refer to the AV release notes, if needed):

https://live.paloaltonetworks.com/docs/DOC-6220 Page 2 of 8
How to Configure DNS Sinkholing on PAN-OS 6.0 | Palo Alto Networks Live 3/24/15, 5:26 AM

2. Initial DNS request:

3. DNS Response:

https://live.paloaltonetworks.com/docs/DOC-6220 Page 3 of 8
How to Configure DNS Sinkholing on PAN-OS 6.0 | Palo Alto Networks Live 3/24/15, 5:26 AM

Detailed information can be found in the threat log:

https://live.paloaltonetworks.com/docs/DOC-6220 Page 4 of 8
How to Configure DNS Sinkholing on PAN-OS 6.0 | Palo Alto Networks Live 3/24/15, 5:26 AM

Note: Make sure there is a security policy configured to block web-browsing/ssl for IP 1.1.1.1. This generates
block trac logs for malicious users. With this information, a query on the trac logs for "IP 1.1.1.1" and "web-
browsing/ssl" will generate report for malicious users.

owner: rvanderveken

10127 Views Categories: Objects & Security Profiles , Setup, Management & Administration
Tags: dns, anti-spyware, threats, sinkhole, sinkholing

Average User Rating

(13 ratings)

9 Comments

https://live.paloaltonetworks.com/docs/DOC-6220 Page 5 of 8

Das könnte Ihnen auch gefallen