Enable DNS sinkholing by attaching an Anti-Spyware profile to your security rules.
Malicious queries resolve to a default Palo Alto Networks sinkhole IP, to identify infected
hosts.
| Where Can I Use
This? | What Do I Need? |
To enable DNS sinkholing, attach the default
Anti-Spyware profile to a firewall security policy rule (see
Set Up Antivirus, Anti-Spyware, and Vulnerability Protection). DNS queries
to any domain included in the
Palo Alto Networks DNS signature source
that you specify are resolved to the default
Palo Alto Networks sinkhole
IP address. The IP addresses currently are IPv4—sinkhole.paloaltonetworks.com
and a loopback address IPv6 address—::1. These address are subject
to change and can be updated with content updates.