Create Domain Exceptions and Allow Lists (Strata Cloud Manager)
Focus
Advanced DNS Security Powered by Precision AI®

Create Domain Exceptions and Allow Lists (Strata Cloud Manager)

Table of Contents


Create Domain Exceptions and Allow Lists (Strata Cloud Manager)

  1. Use the credentials associated with your Palo Alto Networks support account and log in to the Strata Cloud Manager on the hub.
  2. Add domain overrides in cases where false-positives occur.
    1. Select ConfigurationNGFW and Prisma AccessSecurity ServicesDNS Security and select a DNS Security profile to modify.
    2. Add Override or Delete to modify the domain list entries as necessary. Each additional entry requires the domain and a description.
    3. Click OK to save your modified DNS Security profile.
  3. Reference an external dynamic list (EDL) as part of your DNS Security profile to import third party threat feeds.
    1. Create an domain-based external dynamic list (ConfigurationNGFW and Prisma AccessObjectsExternal Dynamic Lists). For more information about EDLs, see External Dynamic List.
    2. Select ConfigurationNGFW and Prisma AccessSecurity ServicesDNS Security.
    3. In the External Dynamic Lists panel, you should see the EDL created in step 1. Provide the Policy Action and Packet Capture settings.
      For Policy Action, choose bypass to actively exempt trusted domains from DNS Security inspection without generating log entries. Use the bypass action for internal domains or sanctioned applications that don't require DNS-layer security analysis.
      The allow action on domain EDLs has no effect on DNS Security inspection. If a domain matches both an EDL configured with allow and a DNS Security category, the DNS Security action is still applied. To actively exempt trusted domains from inspection, use the bypass action.
      For managed firewalls running PAN-OS versions earlier than 12.2.2, the bypass action is automatically converted to allow when the configuration is pushed. Because the allow action has no effect on DNS Security inspection for domain EDLs, domains in the EDL are still inspected on those firewalls.
    4. Save your changes when you have finished making your updates.