Get Started with Advanced DNS Security
Focus
Focus
Advanced DNS Security Powered by Precision AI®

Get Started with Advanced DNS Security

Table of Contents

Get Started with Advanced DNS Security

Deploy Advanced DNS Security on Amazon Route 53 Resolver DNS Firewall to protect VPC DNS query traffic from advanced threats.
Where Can I Use This?What Do I Need?
  • Amazon Route 53 Resolver DNS Firewall
  • Advanced DNS Security subscription (AWS Marketplace)
  • AWS account with Route 53 DNS Firewall access
  • Advanced plan pricing option for your rule group
  • One or more VPCs to protect
Palo Alto Networks® Advanced DNS Security on Amazon Route 53 Resolver DNS Firewall delivers cloud-native DNS threat protection for your Amazon VPCs without requiring you to deploy separate firewalls or reconfigure VPC settings to redirect DNS query traffic. The integration provides 30+ DNS threat detections—including command-and-control (C2), domain generation algorithms (DGA), DNS tunneling, fast flux, and newly registered domains—through the high-availability infrastructure of Route 53 DNS Firewall. See Supported AWS Regions for availability.
Advanced DNS Security on Route 53 DNS Firewall uses three types of threat detection models that work together to identify malicious domains. Inline detectors evaluate DNS queries in the path of resolution and provide instant verdicts for known threats and DGA patterns. Real-time detectors monitor queries off-path and generate signals within seconds for threats such as tunneling and rebinding. Offline detectors passively analyze domain patterns to identify domain squatting, strategically-aged domains, phishing, and ransomware domains. When any model identifies a malicious domain, the finding is applied to one or more DNS security categories that you select when creating DNS Firewall rules.
The integration uses a fail-open architecture for DGA detection—if a threat verdict is delayed beyond a 4-millisecond timeout, DNS queries continue without disruption. Other detection categories have no timeout. You can combine Palo Alto Networks DNS security rules with AWS Managed Domain Lists in the same rule group for layered protection that covers both Palo Alto Networks threat intelligence and AWS-native DNS protections.
You manage subscriptions, rules, rule groups, and VPC associations through the DNS Firewall section of the Amazon VPC console. The Route 53 interface and workflows are subject to change. Refer to the Amazon Route 53 Resolver DNS Firewall documentation for the most current information on DNS Firewall console navigation, rule configuration options, and VPC association management.
Configuring Advanced DNS Security on Route 53 DNS Firewall involves four steps:
  1. Subscribe through the DNS Firewall console or AWS Marketplace.
  2. Create DNS Firewall rules by selecting Palo Alto Networks DNS security categories and specifying actions.
  3. Associate rule groups with VPCs to enforce DNS threat protections across your organization.
  4. Monitor DNS query activity through AWS CloudWatch metrics and Security Hub findings.
Before deploying to production, review the best practices.

Rule States

Palo Alto Networks partner managed rules in DNS Firewall can have different sync states that indicate their operational status:
StateDescriptionRecommended Action
CREATEDThe rule has been successfully created and is being enforced normally.No action needed.
CREATINGThe rule is currently being created, pending an entitlement check. If you are subscribed to the Palo Alto Networks product, the rule transitions to CREATED.Wait for the rule to transition to CREATED. If the rule remains in this state, verify your subscription is active.
CREATION_FAILEDThe rule failed to create because you are not subscribed to the Palo Alto Networks product.Either subscribe to the product in AWS Marketplace, or remove the rule from the rule group.
You can check rule status from the Status column in the DNS Firewall rules table for your rule group.
For questions related to Advanced DNS Security functionality, contact adns-support@paloaltonetworks.com.