Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
MENU
Home
DNS Security
DNS Security Administration
PAN-OS 10.0 and later
Document:
DNS Security Administration
PAN-OS 10.0 and later
Last Updated:
Wed Mar 15 01:02:16 UTC 2023
Table of Contents
Filter
About DNS Security
Cloud-Delivered DNS Signatures and Protections
DNS Security Data Collection and Logging
DNS Security Service Domains
Configure DNS Security
Enable DNS Security
Prisma Access
PAN-OS
PAN-OS 11.0 and Later
PAN-OS 10.0
PAN-OS 9.1
Configure DNS-Over-TLS
Prisma Access
PAN-OS
Configure DNS-Over-DoH
Prisma Access
PAN-OS
Create Domain Exceptions and Allow | Block Lists
Create Domain Exceptions and Allow | Block Lists (Prisma Access)
PAN-OS
Create domain signature exceptions and allow lists in PAN-OS 10.0 and later
Create domain signature exceptions in PAN-OS 9.1
DNS Security Test Domains
Test Connectivity to the DNS Security Service
Configure Lookup Timeout
Bypass DNS Security
Prisma Access
PAN-OS
PAN-OS 10.0
PAN-OS 9.1
Monitor DNS Security
View DNS Security Dashboard
DNS Security Dashboard Cards
Prisma Access
AIOps
View DNS Security Logs
Prisma Access
PAN-OS
AIOps
Cortex Data Lake
About DNS Security
Cloud-Delivered DNS Signatures and Protections
DNS Security Data Collection and Logging
DNS Security Service Domains
Configure DNS Security
Enable DNS Security
Configure DNS-Over-TLS
Configure DNS-Over-DoH
Create Domain Exceptions and Allow | Block Lists
DNS Security Test Domains
Test Connectivity to the DNS Security Service
Configure Lookup Timeout
Bypass DNS Security
Monitor DNS Security
View DNS Security Dashboard
DNS Security Dashboard Cards
View DNS Security Logs
Previous
Next
PAN-OS 10.0 and later
Log in to the NGFW.
Add domain signature exceptions in cases where false-positives occur.
Select
Objects
Security Profiles
Anti-Spyware
.
Select a profile to modify.
Add
or modify the Anti-Spyware profile from which you want to exclude the threat signature, and select
DNS Exceptions
.
Search for a DNS signature to exclude by entering the name or FQDN.
Select the checkbox for each
Threat ID
of the DNS signature that you want to exclude from enforcement.
Click
OK
to save your new or modified Anti-Spyware profile.
Add an allow list to specify a list of DNS domains / FQDNs to be explicitly allowed.
Select
Objects
Security Profiles
Anti-Spyware
.
Select a profile to modify.
Add
or modify the Anti-Spyware profile from which you want to exclude the threat signature, and select
DNS Exceptions
.
To
Add
a new FQDN allow list entry, provide the DNS domain or FQDN location and a description.
Click
OK
to save your new or modified Anti-Spyware profile.
Previous
Next
Most Popular
Recommended For You
Recommended Videos
Recommended videos not found.