Verify Advanced IP Defense Cloud Connectivity
Focus
Focus
Advanced IP Defense

Verify Advanced IP Defense Cloud Connectivity

Table of Contents

Verify Advanced IP Defense Cloud Connectivity

Monitor the health of communication between your enforcement point and the Advanced IP Defense cloud service to ensure reliable threat detection.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • Advanced IP Defense license
  • PAN-OS 12.2.3 and later
Advanced IP Defense depends on continuous communication with the Advanced IP Defense Regional Service Domains over TCP 443 for real-time IP attribute lookups, direct-to-IP detection, and allow list updates. If this communication degrades, the enforcement point falls back to locally cached data or fails open, reducing detection coverage.

Cloud Message Types

The enforcement point exchanges two types of messages with Advanced IP Defense during normal operation:
  • DNS response copies—IP-TTL pairs from A and AAAA records forwarded to the cloud to build a per-tenant DNS state table. The cloud uses this table to answer DNS-seen queries during lookup requests.
  • Advanced IP Defense lookup requests—Queries for IP attributes and DNS-seen status when the enforcement point encounters a cache miss.

Allowlist Updates

The enforcement point periodically pulls two per-tenant allow list files from a cloud storage bucket: one for the Advanced IP Defense allow list and one for the direct-to-IP allow list. If the enforcement point cannot reach the storage endpoint, it continues to use the most recently cached version of the allow lists.

Verify Connectivity from the CLI

Run the following command on the enforcement point CLI to check Advanced IP Defense cloud connectivity status:
show ip-defense status
Verify that Cloud connection shows Connected and Last Result shows Good.
admin@PA-XXXX> show ip-defense status

Advanced IP Defense cloud
License:                        Valid
Configurations:                 Enabled
Current cloud server:           api.prod.aipd.service.paloaltonetworks.com
Cloud connection:               Connected
Last Result:                    Good ( 14 sec ago )
Allowlist Refresh:              Interval 1800 sec ( Due 944 sec )
Last up time:                   2026/08/21 15:22:39  to now
Last down time:                 N/A

Cookies Information :
Region state:                   Assigned
Region ID:                      us-central1
Region timestamp:               2026/08/21 15:22:39
TSG state:                      Assigned
TSG ID:                         1234567890
TSG timestamp:                  2026/08/21 15:22:39

Certificate Information :
Thermite : Available
Subject : CN = 00XXXXXXXXXXX, O = Palo Alto Networks, L = Santa Clara, ST = CA, C = US
Issuer : CN = USC-Client-Issuing-CA2-G5, O = Palo-Alto-Networks-Inc., C = US
CA : no
Not-valid-before : Aug 17 23:03:01 2026 GMT
Not-valid-after : Nov 15 23:03:00 2026 GMT
Key fields to check:
  • License—Must show Valid. If not, verify your license activation in the Customer Support Portal.
  • Cloud connection—Must show Connected. If disconnected, check network connectivity to Advanced IP Defense endpoints on TCP 443.
  • Allowlist Refresh—Shows the refresh interval and time until the next pull. Confirms the enforcement point is actively retrieving allow list updates.
  • Region state—Must show Assigned. Indicates the enforcement point has been assigned to a regional cloud endpoint.