DNS Signature Lookup Automatic Recovery
Focus
Focus
Advanced DNS Security Powered by Precision AI®

DNS Signature Lookup Automatic Recovery

Table of Contents

DNS Signature Lookup Automatic Recovery

Enable automatic recovery for DNS signature lookups so the firewall preserves DNS traffic flow when cloud connectivity is degraded.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • CN-Series
  • Advanced DNS Security License or DNS Security License
  • Advanced Threat Prevention or Threat Prevention License
  • PAN-OS 12.1.2 or later
When the firewall sends a DNS signature lookup request to the Advanced DNS Security cloud, it expects a response within a short time window. If the cloud is unreachable or experiencing latency, the data plane does not receive a timely reply and drops DNS response packets while waiting — causing DNS resolution delays for end users.
DNS Signature Lookup Health Monitor enables the firewall to passively track the success, failure, and timeout rates of your existing DNS lookup traffic to the Advanced DNS Security cloud. By monitoring live traffic, the firewall evaluates cloud reachability in real-time and can automatically preserve traffic flow during connectivity disruptions without generating additional synthetic test traffic. When connectivity returns to normal, the firewall resumes cloud-based DNS signature lookups automatically.
This setting is disabled by default. Enable it when you want the firewall to automatically preserve DNS traffic flow during cloud connectivity disruptions rather than dropping DNS responses.

Strata Cloud Manager

Enable DNS Signature Lookup Health Monitor on firewalls managed through Strata Cloud Manager.
  1. Log in to Strata Cloud Manager on the hub.
  2. Select ConfigurationNGFW and Prisma AccessSecurity ServicesDNS Security and then go to the Settings tab.
  3. Enable Enable DNS Signature Lookup Health Monitor.
  4. Click Save.

PAN-OS & Panorama

Enable DNS Signature Lookup Health Monitor on a firewall managed through the PAN-OS web interface or Panorama.
  1. Select DeviceSetupContent-ID.
  2. Edit the Realtime Signature Lookup settings.
  3. Enable Enable DNS Signature Lookup Health Monitor.
  4. Click OK.
  5. Click Commit.
Verify and Troubleshoot DNS Signature Lookup Recovery
To verify the operational status of the monitor and troubleshoot cloud connectivity issues, use the following CLI commands:
  • show running dns-rtsig-monitor—Displays the running status of the health monitor for each data plane, including the current health status (Current status), monitoring interval (Interval), number of status changes, and the last time the status changed. The output shows a separate entry for each data plane on the firewall.
  • show dns-proxy dns-signature info—Displays the current cloud connection status (Last Result), the time since the last successful connection, and the server address (Last Server Address).
  • show counter global | match ctd_dns_rtsig_wait_pkt_drop_skip—Tracks the number of times the firewall successfully mitigated a dropped packet by modifying the TTL during an unhealthy cloud connection state. This counter only appears when the firewall has mitigated at least one dropped packet.
Example output for show running dns-rtsig-monitor:
admin@PA-5560> show running dns-rtsig-monitor

DP s1dp0:

DNS RTSIG lookup monitor:       Active
Interval:                       3000ms
Start time:                     Thu May 15 17:19:52 2025
Current status:                 Healthy
Number of status changes:       2
Last time status changed:       Thu May 15 17:56:46 2025

DP s1dp1:

DNS RTSIG lookup monitor:       Active
Interval:                       3000ms
Start time:                     Thu May 15 17:19:52 2025
Current status:                 Healthy
Number of status changes:       2
Last time status changed:       Thu May 15 17:56:45 2025
Example output for show dns-proxy dns-signature info:
admin@PA-5560> show dns-proxy dns-signature info

Cloud URL: dns.service.paloaltonetworks.com:443
Telemetry URL: io.dns.service.paloaltonetworks.com:443
Last Result: Good ( 325 sec ago )
Last Server Address: 198.135.184.156
Parameter Exchange: Interval 1800 sec
Allow List Refresh: Interval 86400 sec ( Due 53675 sec )
Request Waiting Transmission: 0
Request Pending Response: 0
Cache Size: 5000