Configure Advanced DNS Security Resolver for DoT
Focus
Focus
Advanced DNS Security Powered by Precision AI®

Configure Advanced DNS Security Resolver for DoT

Table of Contents

Configure Advanced DNS Security Resolver for DoT

The Advanced DNS Security Resolver supports analysis and categorization of DNS payloads contained within encrypted DNS traffic requests to DNS hosts using DoT.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Advanced DNS Security Resolver License
You can configure the Advanced DNS Security Resolver to analyze and categorize DNS payloads contained within encrypted DNS traffic requests to DNS hosts using DoT. DNS over TLS (DoT) is a security protocol that encrypts DNS queries using TLS over TCP port 853, preventing eavesdropping and manipulation of DNS traffic between the client and resolver. DoT is specified in RFC 7858, with operational guidance in RFC 8310.
The Advanced DNS Security Resolver DoT implementation uses the same dedicated domain as DNS over HTTPS (edge-dns.service.paloaltonetworks.com). The service requires a minimum of TLS 1.2, with TLS 1.3 preferred. Clients must connect using the domain name — connecting by server IP address directly is not supported. Mutual TLS (mTLS) is not supported.
  1. Enable your Advanced DNS Security Resolver. When defining your connection sources, be sure to include the public IPs and public subnets that would be used to send traffic to the DNS resolver.
  2. Retrieve the FQDN used to facilitate DNS-over-TLS queries.
    1. Select ConfigurationADNS Resolver and then go to the DNS Resolver Configurations tab.
    2. In the DNS Resolver Info window, refer to the DNS over TLS field.
      The DNS Resolver Info window displays the DoT endpoint alongside the primary and secondary IP addresses and the DoH endpoint. Use the copy icon to copy the FQDN.
  3. Configure your client devices to use the Advanced DNS Security Resolver FQDN (edge-dns.service.paloaltonetworks.com) for DNS-over-TLS queries on TCP port 853.
    The method for configuring DoT varies by client operating system and DNS client application. Specify the Advanced DNS Security Resolver domain name as the DoT server — do not use the IP address directly.
  4. (Optional) Search for TLS-encrypted DNS queries that have been processed using the Advanced DNS Security Resolver.
    1. Select Log Viewer and use the drop down to select the DNS Security (Resolver and SDWAN and Panos 12.1 or later) log type.
    2. Submit a log query based on the application, using dns-over-tls, for example, app = 'dns-over-tls'.
    3. Select a log entry to view the details of a detected DNS threat that uses DoT.
    4. The threat Application is displayed in the General pane of the detailed log view. Other relevant details about the threat are displayed in their corresponding windows.