You
subscribe to
Advanced DNS Security directly
from the Route 53 DNS Firewall console through AWS Marketplace. After subscribing,
you
create DNS Firewall rules by selecting one
or more
Palo Alto Networks DNS security categories and specifying an action to
block or alert on matching queries. You assign each rule a priority to control
evaluation order, then add the rules to a rule group that you can share and
associate with one or more VPCs and accounts in your organization using AWS Resource
Access Manager (RAM). You can also distribute subscriptions across multiple accounts
using AWS License Manager.
The integration uses a fail-open architecture to maintain DNS resolution
availability—if a threat verdict is delayed, DNS queries continue without
disruption. You can combine Palo Alto Networks DNS security rules with AWS Managed
Domain Lists in the same rule group for layered protection. The feature covers both
VPC DNS query traffic and hybrid-cloud traffic forwarded through Route 53 Resolver
Endpoints or Route 53 Global Resolver, giving you unified DNS threat protection
across AWS and on-premises environments from the Advanced DNS Security
subscription.