A network security administrator encounters an issue where the Palo Alto Networks firewall is unable to resolve external domain names, impacting features like URL filtering and cloud-based threat intelligence updates. The internal DNS servers are functioning correctly. Which basic network configuration step was MOST likely overlooked on the firewall itself?
- AThe default gateway for the management interface is not configured or is incorrect.
- BThe firewall is not subscribed to the Threat Prevention license.
- CThe DNS proxy settings are misconfigured or disabled.
- DThe firewall's management interface is configured with a static IP address.
Show answer & explanationAnswer & explanation
Correct answer: A. The default gateway for the management interface is not configured or is incorrect.
If the firewall cannot resolve external domain names, it indicates an issue with its own ability to reach external DNS servers. The most common reason for this, assuming internal DNS works, is that the firewall's management interface (which it uses for its own DNS queries, updates, etc.) cannot reach the internet because its default gateway is missing or incorrect.
Why the other options are wrong
- B. Lack of a Threat Prevention license would prevent threat updates, but the core issue described is 'unable to resolve external domain names,' which points to a fundamental network connectivity problem for the firewall's own DNS lookups.
- C. While DNS proxy can be configured, the firewall itself needs to resolve names for its own operations. The primary issue here is basic network reachability for the firewall's own queries, not necessarily client DNS proxying.
- D. A static IP is a valid configuration and doesn't inherently prevent DNS resolution.
Firewall DNS Resolution
Palo Alto Networks firewalls rely on DNS for their own operations, including content updates, cloud services, and external name resolution, which requires proper network configuration.
- Firewall uses its management interface for its own DNS queries.
- Requires correct DNS server and default gateway configuration.
- Impacts updates, cloud services, and URL filtering.
Memory trick: Firewall can't find the internet's name, if its own gateway isn't playing the game!