Create Domain Exceptions and Allow Lists
Manage false positives by adding signature exceptions or safe domain lists to bypass DNS
analysis.
| Where Can I Use
This? | What Do I Need? |
Prisma Access NGFW VM-Series CN-Series
|
|
DNS Security creates threat signatures for domains that have been analyzed by the
DNS Security service. For these known domains, the signatures are referenced when a DNS
query is received. In some cases, it might be possible that the signature has
incorrectly categorized a domain as a threat, due to certain features or qualities
present in the domain. In such circumstances, you can add signature exceptions to bypass
these false-positives.
If there are known safe domains that are categorized as malicious, such as
internal domains, you can add a list of domains that will bypass any DNS analysis. If
your organization uses third party threat feeds as part of a comprehensive threat
intelligence solution, you can also reference those in the form of external dynamic
lists (EDLs) in your DNS Security profile.
You can specify up to a maximum of 100 DNS signature exceptions and 100 DNS
domain/FQDN entries in an allow list. If you require an allow list with more
than 100 domain/FQDN entries, you can reference an external dynamic list
(EDL) in your DNS Security profile with a policy action of
bypass (PAN-OS 12.2.2 and later) to actively exempt those domains
from inspection.
To bypass DNS or Advanced DNS Security categories, use the
allow action in the Anti-Spyware profile DNS Policies tab. To
bypass specific domains using an external dynamic list (EDL), use the
bypass action on the EDL in your DNS Security profile (PAN-OS
12.2.2 and later).
The allow action on domain EDLs has no effect on DNS Security
inspection. Domains matching an EDL configured with allow are still
processed as part of the regular DNS Security pipeline. To actively exempt
trusted domains from inspection, use the bypass action (PAN-OS 12.2.2
and later).
Do not add UTIDs from 109,000,000 to 109,029,999 to the
DNS
Signature Exception list. These Universal Threat IDs
represent malicious categories, not individual domains, unlike other threat
signatures. The UTID number (seen as
ID in the Threat
logs) identifies the specific
DNS detection method DNS Security
uses for domain classification.
Create Domain Exceptions and Allow Lists (Strata Cloud Manager)
Use the credentials associated with your
Palo Alto Networks support account and
log in to the
Strata Cloud Manager on the
hub.
Add domain overrides in cases where false-positives occur.
Select and select a DNS Security profile to modify.
Add Override or
Delete to
modify the domain list entries as necessary. Each additional entry requires
the domain and a description.
Click
OK to save your modified
DNS Security profile.
Reference an external dynamic list (EDL) as part of your
DNS Security profile to import third party threat feeds.
Create an domain-based external dynamic list (). For more information about EDLs, see
External Dynamic List.
Select .
In the
External Dynamic Lists panel, you should
see the EDL created in step 1. Provide the
Policy
Action and
Packet Capture
settings.
For Policy Action, choose
bypass to actively exempt trusted domains
from DNS Security inspection without generating
log entries. Use the bypass action for internal domains or
sanctioned applications that don't require DNS-layer security
analysis.
The allow action on domain EDLs has no
effect on DNS Security inspection. If a domain matches both an EDL
configured with allow and a DNS Security category, the DNS Security
action is still applied. To actively exempt trusted domains from
inspection, use the bypass action.
For managed firewalls running PAN-OS versions earlier than 12.2.2,
the bypass action is automatically converted to allow when the
configuration is pushed. Because the allow action has no effect on
DNS Security inspection for domain EDLs, domains in the EDL are
still inspected on those firewalls.
Save your changes when you have finished making
your updates.
Create Domain Exceptions and Allow Lists (NGFW (Managed by PAN-OS or Panorama))
PAN-OS 10.0 and later releases provide
an additional option to explicitly add allowable domains through
the Anti-Spyware security profile. You can add domain/FQDN entries
for approved domain sources if they trigger a false-positive response
from DNS Security.
Create Domain Exceptions and Allow Lists (PAN-OS 10.0 and later)
Log in to the NGFW. Add domain signature exceptions in cases where false-positives
occur.
Select .
Select a profile to modify.
Add or modify the Anti-Spyware
profile from which you want to exclude the threat signature, and
select
DNS Exceptions.
Search for a DNS signature to exclude by entering
the name or FQDN.
Select the checkbox for each
Threat
ID of the DNS signature that you want to exclude from enforcement.
Click
OK to save your new or
modified Anti-Spyware profile.
Add an allow list to specify a list of DNS domains /
FQDNs to be explicitly allowed.
Select .
Select a profile to modify.
Add or modify the Anti-Spyware
profile from which you want to exclude the threat signature, and
select
DNS Exceptions.
To
Add a new FQDN allow list
entry, provide the DNS domain or FQDN location and a description.
Click
OK to save your new or
modified Anti-Spyware profile.
(
Optional) Reference an existing domain external dynamic list (EDL) with
the
bypass action to exempt trusted domains from DNS Security inspection without generating log entries (PAN-OS 12.2.2 and later).
Select .
Select a profile to modify, then select the
DNS
Policies tab.
In the
External Dynamic Lists section, select a domain EDL and
for
Policy Action, choose
bypass.
The allow action on domain EDLs has no effect on DNS Security
inspection. If a domain matches both an EDL configured with allow and a DNS Security
category, the DNS Security action is still applied. To actively exempt trusted domains
from inspection, use the bypass action.
Click OK to save your changes.
Create Domain Exceptions and Allow Lists (PAN-OS 9.1)
Allow and block lists are not available
in PAN-OS 9.1.
Log in to the NGFW. Add domain signature exceptions in cases where false-positives
occur.
Select .
Select a profile to modify.
Add or modify the Anti-Spyware
profile from which you want to exclude the threat signature, and
select
DNS Signatures > Exceptions.
Search for a DNS signature to exclude by entering
the name or FQDN.
Select the
DNS Threat
ID for the DNS signature that you want to exclude from
enforcement.
Click OK to save your new or
modified Anti-Spyware profile.