Configure Advanced DNS Security Resolver to provide DNS security protection when
Prisma Access Agent cannot establish tunnel connections or when users disconnect from the
tunnel.
| Where Can I Use This? | What Do I Need? |
Advanced DNS Security Resolver provides DNS security for your mobile users when the
Prisma Access Agent tunnel is disconnected. This service maintains consistent threat
protection and content filtering by intercepting DNS queries and forwarding them to
Palo Alto Networks resolvers over encrypted HTTPS connections.
Advanced DNS Security Resolver applies DNS Security and enforces DNS policies
that you configured on the Advanced DNS Resolver page in
Strata Cloud Manager.
When to Use Advanced DNS Security Resolver
You should implement Advanced DNS Security Resolver if you want Always-On security
but your mobile users frequently encounter situations where maintaining full tunnel
connectivity is challenging or impractical. Common scenarios include users working
at customer sites where the use of Prisma Access Agent is blocked, experiencing
network performance issues that require tunnel disconnection, or accessing
sanctioned SaaS applications that perform better with direct connectivity.
How Advanced DNS Security Resolver Works
Advanced DNS Security Resolver operates by transparently intercepting DNS queries
from endpoints running Prisma Access Agent. When the tunnel is
disconnected,
the agent forwards these queries to Palo Alto Networks DNS resolvers using
DNS-over-HTTPS (DoH) protocol. The resolvers apply your DNS Security and enforces
your DNS policies before returning the DNS response to the endpoint.
Key Components
Forwarding Profiles define how the system routes DNS traffic. You configure
steering configuration within forwarding profiles to specify when domains should be
resolved by Advanced DNS Security Resolver and when they should use the local DNS
server. You can configure this on a per-application basis.
Authentication Tokens enable secure, authorized communication between Prisma
Access Agent and Advanced DNS Security Resolver. The system uses user access tokens
for policy enforcement and device tokens for longer-term authentication when users
do not actively log in.
DoH Connectivity establishes an encrypted communication channel between an
endpoint and the Palo Alto Networks DNS resolver. Advanced DNS Security Resolver
maintains primary and secondary resolvers for redundancy.
When you configure Advanced DNS Security Resolver, it provides seamless DNS security
that activates automatically based on your configuration and current endpoint
network conditions.