.
Verify and Troubleshoot DNS Signature Lookup Recovery
To verify the operational status of the monitor and troubleshoot cloud connectivity
issues, use the following CLI commands:
Example output for show running dns-rtsig-monitor:
admin@PA-5560> show running dns-rtsig-monitor
DP s1dp0:
DNS RTSIG lookup monitor: Active
Interval: 3000ms
Start time: Thu May 15 17:19:52 2025
Current status: Healthy
Number of status changes: 2
Last time status changed: Thu May 15 17:56:46 2025
DP s1dp1:
DNS RTSIG lookup monitor: Active
Interval: 3000ms
Start time: Thu May 15 17:19:52 2025
Current status: Healthy
Number of status changes: 2
Last time status changed: Thu May 15 17:56:45 2025
Example output for show dns-proxy dns-signature info:
admin@PA-5560> show dns-proxy dns-signature info
Cloud URL: dns.service.paloaltonetworks.com:443
Telemetry URL: io.dns.service.paloaltonetworks.com:443
Last Result: Good ( 325 sec ago )
Last Server Address: 198.135.184.156
Parameter Exchange: Interval 1800 sec
Allow List Refresh: Interval 86400 sec ( Due 53675 sec )
Request Waiting Transmission: 0
Request Pending Response: 0
Cache Size: 5000