| Where Can I Use This? | What Do I Need? |
- Amazon Route 53 Resolver DNS Firewall
|
- Advanced DNS Security subscription (active)
- DNS Firewall rule group with Palo Alto Networks rules
- Target VPCs identified
|
After creating DNS Firewall rules with Advanced DNS Security security categories, you associate the rule group containing those rules with one or more VPCs to begin enforcing DNS threat protections. You can associate a rule group with VPCs in the same account or share it across multiple AWS accounts in your organization.
DNS Firewall begins evaluating DNS queries from associated VPCs immediately after association. For DGA detection, a fail-open architecture ensures that if a verdict is delayed beyond 4 milliseconds, DNS queries continue resolving normally—your workloads experience no disruption.
Advanced DNS Security evaluates internet-bound DNS queries (public domains) from associated VPCs. Internal domains resolved within a VPC are not evaluated by Advanced DNS Security.