Sinkhole forges a response to a DNS query for domains that match the DNS
category configured for a sinkhole action to the specified
sinkhole server, to assist in identifying compromised hosts.
When the default sinkhole FQDN (sinkhole.paloaltonetworks.com)
is used, the firewall sends the CNAME record as a response to
the client, with the expectation that an internal DNS server
will resolve the CNAME record, allowing malicious communications
from the client to the configured sinkhole server to be logged
and readily identifiable. However, if clients are in networks
without an internal DNS server, or are using software or tools
that cannot be properly resolve a CNAME into an A record
response, the DNS request is dropped, resulting in incomplete
traffic log details that are crucial for threat analysis. In
these instances, you should use the following sinkhole IP
address: (198.135.184.22).