Verify Advanced IP Defense Cloud Connectivity
Focus
Focus
Advanced IP Defense

Verify Advanced IP Defense Cloud Connectivity

Table of Contents


Verify Advanced IP Defense Cloud Connectivity

Monitor the health of communication between your firewall and the Advanced IP Defense cloud service to ensure reliable threat detection.
Where Can I Use This?What Do I Need?
  • PAN-OS 12.2 and later
  • Strata Cloud Manager
  • Advanced IP Defense license
  • Admin access to firewall or Strata Cloud Manager
Advanced IP Defense depends on continuous communication with the cloud service for real-time IP attribute lookups, direct-to-IP detection, and allowlist updates. If this communication degrades, the firewall falls back to locally cached data or fails open, reducing detection coverage. Monitoring cloud connectivity health helps you identify issues before they affect your security posture and distinguish between cloud-side service disruptions and local network or configuration problems.
The firewall exchanges two types of messages with the Advanced IP Defense cloud service during normal operation. DNS response copies (IP-TTL pairs from A and AAAA records) are forwarded to the cloud to build a per-tenant DNS state table used for direct-to-IP detection. AIPD lookup requests query the cloud for IP attributes when the firewall encounters a cache miss. A healthy deployment shows a steady flow of both message types. A drop in lookup volume may indicate a connectivity issue, while a spike may indicate that cached attributes are expiring faster than expected or that the Bloom filter (negative cache) needs refreshing.
In addition to real-time lookups, the firewall periodically pulls two per-tenant allowlist files from a cloud storage bucket: one for the AIPD allowlist and one for the no-DNS allowlist. These pulls occur at regular intervals. If the firewall can't reach the storage endpoint, it continues to use the most recently cached version of the allowlists, but entries may become stale over time. You can verify allowlist freshness by checking the timestamp of the last successful pull.
You can check the overall operational status of the Advanced IP Defense cloud service on the Palo Alto Networks Service Status Page. This page provides real-time incident reports, performance degradation notices, and scheduled maintenance windows for all cloud-delivered security services, including Advanced IP Defense. The service status can display as Operational, Degraded Performance, or Service Unavailable.
Health IndicatorWhat It Tells YouWhere to Check
Cloud lookup volumeWhether the firewall is actively querying the cloud for IP attributes. A sudden drop indicates a connectivity issue or a misconfiguration.Advanced IP Defense dashboard (AIPD Cloud Traffic widget) in Strata Cloud Manager
Cloud lookup timeout rateThe percentage of cloud lookups that exceed the configured timeout. A high timeout rate means more traffic is being fail-opened without attribute checks.Threat logs filtered for Advanced IP Defense entries with no attribute match
Allowlist last update timestampWhether the firewall is successfully pulling fresh allowlist files from the cloud storage bucket. A stale timestamp indicates a connectivity issue to the storage endpoint.Firewall system logs or cloud service status in PAN-OS
DNS state table sizeWhether the firewall's DNS cache is approaching maximum capacity. When the cache is full, the firewall fails open on direct-to-IP detection.Firewall system resources in PAN-OS
Cloud service statusWhether the Advanced IP Defense cloud service is operational, experiencing degraded performance, or unavailable.Palo Alto Networks Service Status Page