Disable Connections to PAN-DB Cloud for Air-Gapped Deployments
Focus
Focus
Advanced URL Filtering

Disable Connections to PAN-DB Cloud for Air-Gapped Deployments

Table of Contents


Disable Connections to PAN-DB Cloud for Air-Gapped Deployments

Enable Offline Mode on air-gapped firewalls to stop PAN-DB cloud connection attempts, connection error logs, and URL lookup delays.
Where can I use this?What do I need?
  • NGFW (Managed by PAN-OS or Panorama)
  • PAN-OS 10.2.18, 10.2.20, 11.1.14, 11.2.11, 12.1 and later, or 12.2.2 and later
Offline Mode is a Content-ID setting that prevents your Next-Generation Firewall (NGFW) from connecting to the PAN-DB cloud. Without this setting, air-gapped NGFWs repeatedly attempt to reach the PAN-DB cloud, log each failed attempt, and experience traffic delays from timed-out URL lookups. When you enable Offline Mode, your NGFW changes behavior on the management plane and data plane. The management plane stops connecting to the PAN-DB cloud and does not generate system logs for cloud connection errors. The data plane returns a not-resolved verdict for all URLs except those matching a custom URL category, eliminating URL lookup delays.
Offline Mode disables all PAN-DB cloud connections, including those that would be initiated by Advanced Threat Prevention or Advanced WildFire, which rely on PAN-DB URL categories regardless of whether you have a URL filtering license.
(PAN-OS 12.2 and later) Before you turn on this feature, you can run the test url-enablement-reason vsys <vsys> CLI command to identify which configuration and licenses enable PAN-DB cloud connectivity.
Ensure your security policy rules handle not-resolved URLs as intended before enabling Offline Mode in a production environment.
Offline Mode overrides the Category Lookup Timeout (sec) setting.
  1. Log in to the NGFW web interface.
  2. Select DeviceSetupContent-ID, and edit the URL Filtering settings.
  3. Enable Offline Mode.
  4. Click OK.
  5. Commit your changes.
    Alternatively, run the set deviceconfig setting pan-url-db offline-mode yes CLI command.
  6. Verify that Offline Mode is active.
    Run the show url-cloud status CLI command and check for the following fields and outputs:
    • PAN-OS 12.1 and earlierCloud connection: not connected
    • PAN-OS 12.2.2 and laterPAN-DB Cloud Connectivity Issues describes the following fields:
      • Cloud connection: not connected
      • Connection status: disabled
      • Offline mode: enabled