PAN-OS & Panorama
Focus
Focus
Advanced DNS Security Powered by Precision AI®

PAN-OS & Panorama

Table of Contents


PAN-OS & Panorama

Enable DNS Signature Lookup Health Monitor on a firewall managed through the PAN-OS web interface or Panorama.
  1. Select DeviceSetupContent-ID.
  2. Edit the Realtime Signature Lookup settings.
  3. Enable Enable DNS Signature Lookup Health Monitor.
  4. Click OK.
  5. Click Commit.
Verify and Troubleshoot DNS Signature Lookup Recovery
To verify the operational status of the monitor and troubleshoot cloud connectivity issues, use the following CLI commands:
  • show running dns-rtsig-monitor—Displays the running status of the health monitor for each data plane, including the current health status (Current status), monitoring interval (Interval), number of status changes, and the last time the status changed. The output shows a separate entry for each data plane on the firewall.
  • show dns-proxy dns-signature info—Displays the current cloud connection status (Last Result), the time since the last successful connection, and the server address (Last Server Address).
  • show counter global | match ctd_dns_rtsig_wait_pkt_drop_skip—Tracks the number of times the firewall successfully mitigated a dropped packet by modifying the TTL during an unhealthy cloud connection state. This counter only appears when the firewall has mitigated at least one dropped packet.
Example output for show running dns-rtsig-monitor:
admin@PA-5560> show running dns-rtsig-monitor

DP s1dp0:

DNS RTSIG lookup monitor:       Active
Interval:                       3000ms
Start time:                     Thu May 15 17:19:52 2025
Current status:                 Healthy
Number of status changes:       2
Last time status changed:       Thu May 15 17:56:46 2025

DP s1dp1:

DNS RTSIG lookup monitor:       Active
Interval:                       3000ms
Start time:                     Thu May 15 17:19:52 2025
Current status:                 Healthy
Number of status changes:       2
Last time status changed:       Thu May 15 17:56:45 2025
Example output for show dns-proxy dns-signature info:
admin@PA-5560> show dns-proxy dns-signature info

Cloud URL: dns.service.paloaltonetworks.com:443
Telemetry URL: io.dns.service.paloaltonetworks.com:443
Last Result: Good ( 325 sec ago )
Last Server Address: 198.135.184.156
Parameter Exchange: Interval 1800 sec
Allow List Refresh: Interval 86400 sec ( Due 53675 sec )
Request Waiting Transmission: 0
Request Pending Response: 0
Cache Size: 5000