| Real-time cloud lookups | On-demand IP attribute queries to the Advanced IP Defense cloud service. |
| Direct-to-IP detection | Identifies outbound connections to IP addresses without a
prior DNS resolution, using a per-tenant DNS state table
maintained by Advanced IP Defense. |
| Zone-based security profiles | Attach profiles to zones for broad coverage across all
traffic crossing a zone boundary. Create match rules using
IP attribute categories, tags, and boolean logic. |
| Granular enforcement actions | Configure alert, block, or deny actions per match rule,
with configurable log severity. |
| Local IP attribute cache | Cache up to 1 million IP attribute entries locally for
low-latency enforcement with configurable cache-miss
behavior. |
| Allowlist updates | Periodic per-tenant allowlist downloads from the cloud
(Advanced IP Defense allowlist and direct-to-IP allowlist) for reduced
false positives. |
| Dedicated threat log subtype | A dedicated ip-defense threat log
subtype with fields for matched category, tag, profile name,
rule name, match direction, and DNS-seen status. |
| Content-delivered categories and tags | IP attribute categories and tags delivered through the
content update package. New categories and tags appear
without a PAN-OS upgrade. |