Follow these steps to troubleshoot URLs classified as not-resolved. Not-resolved
designation typically signals PAN-DB cloud connectivity issues.
| Where can I use
this? | What do I need? |
- NGFW (Managed by PAN-OS or Panorama)
|
Note: Legacy URL filtering licenses are
discontinued, but active legacy licenses are still
supported.
|
URLs are classified as not-resolved if your firewall cannot connect
to the PAN-DB URL filtering cloud service to perform lookups, or if PAN-DB takes too
long to respond to URL queries. PAN-DB may take too long to respond when URL lookup
requests saturate the management plane connection, exhausting the queue and the
category lookup timeout. The cloud connection status and URL classification does not
apply to expired subscription licenses or unlicensed users.
If you have enabled
Offline Mode, URLs classified as
not-resolved is the expected behavior. Offline
Mode prevents cloud connection attempts, so only custom URL categories will be
matched; all other URLs receive the
not-resolved
verdict.
Use the following workflow to troubleshoot why URLs are being classified as
Not-resolved: