: Encrypted DNS for DNS Proxy and the Management Interface
Focus
Focus

Encrypted DNS for DNS Proxy and the Management Interface

Table of Contents

Encrypted DNS for DNS Proxy and the Management Interface

Use encrypted DNS on the firewall when it's acting as a DNS proxy or on the firewall's management interface to help maintain privacy and protect DNS traffic.
When your operating systems and web browsers use DNS, securing such DNS traffic with encryption helps maintain privacy and protect the traffic from man-in-the-middle attacks. When your PAN-OS firewall acts as a DNS proxy, you can enable encrypted DNS and specify that the DNS proxy will accept one or more types of DNS communication from the client: DNS-over-HTTP (DoH), DNS-over-TLS (DoT), or cleartext.
You also select the type of encrypted DNS that the DNS proxy will use with DNS servers. In the event that the DNS server rejects encrypted DNS or the DNS proxy receives no response from the primary or secondary server within a timeout period, you have the option to fall back to unencrypted DNS communications with the server.
Additionally, you can enable encrypted DNS on the firewall's management interface such that DNS requests use DoH, DoT, or optionally fall back to unencrypted DNS.

Recommended For You