In the
External Dynamic Lists panel, you should
see the EDL created in step 1. Provide the
Policy
Action and
Packet Capture
settings.
For Policy Action, choose
bypass to actively exempt trusted domains
from DNS Security inspection without generating
log entries. Use the bypass action for internal domains or
sanctioned applications that don't require DNS-layer security
analysis.
The allow action on domain EDLs has no
effect on DNS Security inspection. If a domain matches both an EDL
configured with allow and a DNS Security category, the DNS Security
action is still applied. To actively exempt trusted domains from
inspection, use the bypass action.
For managed firewalls running PAN-OS versions earlier than 12.2.2,
the bypass action is automatically converted to allow when the
configuration is pushed. Because the allow action has no effect on
DNS Security inspection for domain EDLs, domains in the EDL are
still inspected on those firewalls.
Save your changes when you have finished making
your updates.