Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
>
Clear
Create Domain Exceptions and Allow | Block Lists (PAN-OS 10.0 and later)
Updated on
Sep 20, 2024
Focus
Download PDF
Updated on
Sep 20, 2024
Focus
Home
Advanced DNS Security Powered by Precision AI™
Configure DNS Security Subscription Services
Create Domain Exceptions and Allow | Block Lists
Create Domain Exceptions and Allow | Block Lists (NGFW (Managed by PAN-OS or Panorama))
Create Domain Exceptions and Allow | Block Lists (PAN-OS 10.0 and later)
Download PDF
Advanced DNS Security Powered by Precision AI™
Create Domain Exceptions and Allow | Block Lists (PAN-OS 10.0 and later)
Table of Contents
Filter
Expand All
|
Collapse All
Advanced DNS Security
Administration
Create Domain Exceptions and Allow | Block Lists (PAN-OS 10.0 and later)
Log in to the NGFW.
Add domain signature exceptions in cases where false-positives occur.
Select
Objects
Security Profiles
Anti-Spyware
.
Select a profile to modify.
Add
or modify the Anti-Spyware profile from which you want to exclude the threat signature, and select
DNS Exceptions
.
Search for a DNS signature to exclude by entering the name or FQDN.
Select the checkbox for each
Threat ID
of the DNS signature that you want to exclude from enforcement.
Click
OK
to save your new or modified Anti-Spyware profile.
Add an allow list to specify a list of DNS domains / FQDNs to be explicitly allowed.
Select
Objects
Security Profiles
Anti-Spyware
.
Select a profile to modify.
Add
or modify the Anti-Spyware profile from which you want to exclude the threat signature, and select
DNS Exceptions
.
To
Add
a new FQDN allow list entry, provide the DNS domain or FQDN location and a description.
Click
OK
to save your new or modified Anti-Spyware profile.