Manage Advanced IP Defense Connectivity Settings in PAN-OS and Panorama
Focus
Focus
Advanced IP Defense

Manage Advanced IP Defense Connectivity Settings in PAN-OS and Panorama

Table of Contents


Manage Advanced IP Defense Connectivity Settings in PAN-OS and Panorama

Configure the Advanced IP Defense cloud endpoint and verify connectivity from your firewall.
Before configuring Advanced IP Defense connectivity, ensure:
  • Enforcement points can reach Advanced IP Defense endpoints on TCP 443. If your enforcement point is behind a proxy, configure proxy settings under DeviceSetupServices.
  • DNS servers are configured and can resolve Advanced IP Defense domain names. For the full list of domains, see Regional Service Domains.
The Advanced IP Defense connectivity settings control which cloud endpoint the enforcement point uses for real-time IP attribute lookups and direct-to-IP detection. The enforcement point communicates with Advanced IP Defense over TLS on TCP 443.
  1. Log in to the PAN-OS web interface.
  2. Select DeviceSetupContent-ID.
  3. In the Advanced IP Defense Settings section, click the edit icon.
  4. Set the AIPD Cloud Endpoint to a Regional Service Domains FQDN.
    By default, enforcement point uses the global anycast FQDN, which routes lookups to the nearest regional server. You can configure a specific regional FQDN for latency optimization or data residency requirements.
  5. Click OK and Commit your changes.
  6. Verify connectivity by running the following CLI command:
    show ip-defense status
    A successful response confirms that the enforcement point can reach Advanced IP Defense. Verify that Cloud connection shows Connected and Last Result shows Good.
    admin@PA-XXXX> show ip-defense status
    
    Advanced IP Defense cloud
    License:                        Valid
    Configurations:                 Enabled
    Current cloud server:           api.prod.aipd.service.paloaltonetworks.com
    Cloud connection:               Connected
    Last Result:                    Good ( 14 sec ago )
    Allowlist Refresh:              Interval 1800 sec ( Due 944 sec )
    Last up time:                   2026/08/21 15:22:39  to now
    Last down time:                 N/A
    
    Cookies Information :
    Region state:                   Assigned
    Region ID:                      us-central1
    Region timestamp:               2026/08/21 15:22:39
    TSG state:                      Assigned
    TSG ID:                         1234567890
    TSG timestamp:                  2026/08/21 15:22:39
    
    Certificate Information :
    Thermite : Available
    Subject : CN = 00XXXXXXXXXXX, O = Palo Alto Networks, L = Santa Clara, ST = CA, C = US
    Issuer : CN = USC-Client-Issuing-CA2-G5, O = Palo-Alto-Networks-Inc., C = US
    CA : no
    Not-valid-before : Aug 17 23:03:01 2026 GMT
    Not-valid-after : Nov 15 23:03:00 2026 GMT