Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
MENU
Home
DNS Security
DNS Security Administration
Prisma Access
Document:
DNS Security Administration
Prisma Access
Last Updated:
Mar 15, 2023
Table of Contents
Filter
About DNS Security
Cloud-Delivered DNS Signatures and Protections
DNS Security Data Collection and Logging
DNS Security Service Domains
Configure DNS Security
Enable DNS Security
Prisma Access
PAN-OS
PAN-OS 11.0 and Later
PAN-OS 10.0
PAN-OS 9.1
Configure DNS-Over-TLS
Prisma Access
PAN-OS
Configure DNS-Over-DoH
Prisma Access
PAN-OS
Create Domain Exceptions and Allow | Block Lists
Create Domain Exceptions and Allow | Block Lists (Prisma Access)
PAN-OS
Create domain signature exceptions and allow lists in PAN-OS 10.0 and later
Create domain signature exceptions in PAN-OS 9.1
DNS Security Test Domains
Test Connectivity to the DNS Security Service
Configure Lookup Timeout
Bypass DNS Security
Prisma Access
PAN-OS
PAN-OS 10.0
PAN-OS 9.1
Monitor DNS Security
View DNS Security Dashboard
DNS Security Dashboard Cards
Prisma Access
AIOps
View DNS Security Logs
Prisma Access
PAN-OS
AIOps
Cortex Data Lake
About DNS Security
Cloud-Delivered DNS Signatures and Protections
DNS Security Data Collection and Logging
DNS Security Service Domains
Configure DNS Security
Enable DNS Security
Configure DNS-Over-TLS
Configure DNS-Over-DoH
Create Domain Exceptions and Allow | Block Lists
DNS Security Test Domains
Test Connectivity to the DNS Security Service
Configure Lookup Timeout
Bypass DNS Security
Monitor DNS Security
View DNS Security Dashboard
DNS Security Dashboard Cards
View DNS Security Logs
Previous
Next
Prisma Access
Use the credentials associated with your Palo Alto Networks support account and log in to the Prisma Access application on the
hub
.
Add domain overrides in cases where false-positives occur.
Select
Manage
Configuration
Security Services
DNS Security
and select a DNS Security profile to modify.
Add Override
or
Delete
to modify the domain list entries as necessary. Each additional entry requires the domain and a description.
Click
OK
to save your modified DNS Security profile.
Reference an external dynamic list (EDL) as part of your DNS Security profile to import third party threat feeds.
Create an domain-based external dynamic list (
Manage
Configuration
Security Services
External Dynamic Lists
).
Select
Manage
Configuration
Objects
DNS Security
.
In the
External Dynamic Lists
panel, select an EDL and select the
Policy Action
,
Packet Capture
settings, and in
Apply to Profiles
, select the DNS Security profile for which you want the EDL domain list to apply to.
Click
Save
when you have finished making your updates.
Previous
Next
Most Popular
Recommended For You
Recommended Videos
Recommended videos not found.