Define and verify egress IP addresses in SCM to enforce DNS security policies, block
C2/phishing, and manage internal domain bypasses for ADNSR.
| Where Can I Use
This? | What Do I Need? |
The Advanced DNS Security Resolver requires the identification of specific connection sources
to enforce your organizational security policies. These connection sources represent
the egress IP addresses from your various network environments—including branch
offices, campuses, and data centers—that are authorized to forward DNS traffic for
inspection. By defining these sources, you establish the perimeter within which the
Advanced DNS Security Resolver applies advanced protections such as real-time phishing
detection and command-and-control (C2) blocking. This visibility extends beyond
physical infrastructure to include secure connections managed by Prisma Access
Agent, ensuring that mobile users remain subject to consistent DNS policy
enforcement even when working outside the traditional office environment.
When configuring connection sources in the Strata Cloud Manager for Advanced DNS Security Resolver, you must ensure that all static egress IP addresses are
verified to prevent unauthorized traffic from masquerading as your organization. In
contrast, Prisma Access Agent connections are pre-authenticated through the agent's
native identity management. Once these sources are successfully added and verified,
you can associate them with specific DNS Security profiles to dictate how the
resolver handles various threat categories. It is also essential to configure
internal domain bypass lists during this setup to ensure that private, internal-only
DNS requests are handled locally and not forwarded to the cloud resolver, thereby
avoiding resolution failures for internal resources.
Select from the connection source options below: