Enable Offline Mode on air-gapped firewalls to stop PAN-DB cloud connection attempts,
connection error logs, and URL lookup delays.
| Where can I use
this? | What do I need? |
- NGFW (Managed by PAN-OS or Panorama)
|
PAN-OS 10.2.18, 10.2.20, 11.1.14, 11.2.11, 12.1 and
later, or 12.2.2 and later
|
Offline Mode is a Content-ID setting that prevents your Next-Generation Firewall
(NGFW) from connecting to the PAN-DB cloud. Without this setting, air-gapped NGFWs
repeatedly attempt to reach the PAN-DB cloud, log each failed attempt, and
experience traffic delays from timed-out URL lookups. When you enable Offline Mode,
your NGFW changes behavior on the management plane and data plane. The management
plane stops connecting to the PAN-DB cloud and does not generate system logs for
cloud connection errors. The data plane returns a
not-resolved verdict for all URLs except those
matching a custom URL category, eliminating URL lookup delays.
Offline Mode disables all PAN-DB cloud connections, including those that would be
initiated by Advanced Threat Prevention or Advanced WildFire, which rely on
PAN-DB URL categories regardless of whether you have a URL filtering
license.
(PAN-OS 12.2 and later) Before you turn on this feature, you can run the
test url-enablement-reason vsys
<vsys> CLI command to identify which
configuration and licenses enable PAN-DB cloud connectivity.
Ensure your security policy rules handle
not-resolved URLs as intended before enabling
Offline Mode in a production environment.
Offline Mode overrides the Category Lookup Timeout (sec)
setting.