Create Domain Exceptions and Allow Lists (PAN-OS 10.0 and later)
Focus
Advanced DNS Security Powered by Precision AI®

Create Domain Exceptions and Allow Lists (PAN-OS 10.0 and later)

Table of Contents


Create Domain Exceptions and Allow Lists (PAN-OS 10.0 and later)

  • Add domain signature exceptions in cases where false-positives occur.
    1. Select ObjectsSecurity ProfilesAnti-Spyware.
    2. Select a profile to modify.
    3. Add or modify the Anti-Spyware profile from which you want to exclude the threat signature, and select DNS Exceptions.
    4. Search for a DNS signature to exclude by entering the name or FQDN.
    5. Select the checkbox for each Threat ID of the DNS signature that you want to exclude from enforcement.
    6. Click OK to save your new or modified Anti-Spyware profile.
  • Add an allow list to specify a list of DNS domains / FQDNs to be explicitly allowed.
    1. Select ObjectsSecurity ProfilesAnti-Spyware.
    2. Select a profile to modify.
    3. Add or modify the Anti-Spyware profile from which you want to exclude the threat signature, and select DNS Exceptions.
    4. To Add a new FQDN allow list entry, provide the DNS domain or FQDN location and a description.
    5. Click OK to save your new or modified Anti-Spyware profile.
  • (Optional) Reference an existing domain external dynamic list (EDL) with the bypass action to exempt trusted domains from DNS Security inspection without generating log entries (PAN-OS 12.2.2 and later).
    1. Select ObjectsSecurity ProfilesAnti-Spyware.
    2. Select a profile to modify, then select the DNS Policies tab.
    3. In the External Dynamic Lists section, select a domain EDL and for Policy Action, choose bypass.
      The allow action on domain EDLs has no effect on DNS Security inspection. If a domain matches both an EDL configured with allow and a DNS Security category, the DNS Security action is still applied. To actively exempt trusted domains from inspection, use the bypass action.
    4. Click OK to save your changes.