If your deployment includes
Prisma Browser, a predefined connection source named
Prisma
Browser is present in the connection sources list. This connection
source cannot be modified or removed, with the exception of redefining the
associated DNS Security profile. Prisma Browser connections do not need to be
verified, as identification and authentication are managed internally through the
Advanced DNS Security Resolver console.
Prisma Browser support for Advanced DNS Security Resolver routes DNS traffic from the
browser to the resolver using DNS-over-HTTPS (DoH). When enabled, the browser
resolves DNS queries through Advanced DNS Security Resolver instead of the system DNS client,
providing real-time DNS threat inspection and policy enforcement for all browser
activity. Internal domains and private applications that are configured are
automatically excluded from resolution, ensuring internal resources remain
accessible.
You can configure the resolver to operate in one of two failure modes:
- Fail-open—If Advanced DNS Security Resolver is unavailable, the browser falls back
to default resolution to ensure uninterrupted connectivity.
- Fail-close—If Advanced DNS Security Resolver is unavailable, DNS resolution is
blocked, preventing any queries from bypassing inspection.
Unlike connection sources that are managed directly through the Advanced DNS Security Resolver,
Prisma Browser DoH configuration is defined within the Prisma Browser
console. All Advanced DNS Security Resolver security policy, internal domain, and category
configurations are managed from the Advanced DNS Security Resolver console.