Regional Service Domains (Strata Cloud Manager)
Focus
Focus
Advanced DNS Security Powered by Precision AI®

Regional Service Domains (Strata Cloud Manager)

Table of Contents


Regional Service Domains (Strata Cloud Manager)

You can manually specify the server used to facilitate Advanced DNS Security queries. While Palo Alto Networks recommends using the default global service domain, you can override the selected server if you encounter higher than expected latency or other service-related issues. By default, in Strata Cloud Manager, DNS Security and Advanced DNS Security connects to the global service domains (dns.service.paloaltonetworks.com and adv-dns.service.paloaltonetworks.com,respectively), which then automatically redirect to the regional domain that is closest to the network security platform location.
This setting does not impact how standard DNS Security queries are handled.
The following table lists the service domains used by Advanced DNS Security:
Location
URL
Cape Town, South Africa
dns-za.service.paloaltonetworks.com
Bahrain
dns-bh.service.paloaltonetworks.com
Paris, France
dns-fr.service.paloaltonetworks.com
Tokyo, Japan
dns-jp.service.paloaltonetworks.com
Singapore
dns-sg.service.paloaltonetworks.com
Sydney, Australia
dns-au.service.paloaltonetworks.com
London, England
dns-uk.service.paloaltonetworks.com
Frankfurt, Germany
dns-de.service.paloaltonetworks.com
Eemshaven, Netherlands
dns-nl.service.paloaltonetworks.com
Council Bluffs, Iowa, USA
dns-us-ia.service.paloaltonetworks.com
Ashburn, Northern Virginia, USA
dns-us-va.service.paloaltonetworks.com
The Dalles, Oregon, USA
dns-us-or.service.paloaltonetworks.com
Montreal, Quebec, Canada
dns-ca.service.paloaltonetworks.com
Osasco, São Paulo, Brazil
dns-br.service.paloaltonetworks.com
Los Angeles, California, USA
dns-us-ca.service.paloaltonetworks.com
Hong Kong
The Advanced DNS Security regional service domain in Hong Kong has two FQDN options:
  • dns-hk.service.paloaltonetworks.com
  • dns-cn.service.paloaltonetworks.com
Palo Alto Networks recommends using the dns-cn.service.paloaltonetworks.com FQDN if you experience connectivity or access issues.
Mumbai, India
dns-in.service.paloaltonetworks.com
Tel Aviv, Israel
dns-il.service.paloaltonetworks.com
Seoul, South Korea
dns-kr.service.paloaltonetworks.com
  1. Use the credentials associated with your Palo Alto Networks support account and log in to the Strata Cloud Manager on the hub.
  2. Select ConfigurationNGFW and Prisma AccessSecurity ServicesDNS Security.
  3. Go to the Settings tab in the Advanced DNS Security pane, click on Customize.
  4. In the Advanced DNS Security Settings window, update the DNS Security Server field as necessary and Save when finished.