How To Disable the DNS Security Feature from an Anti-Spyware Profile
21684
Created On 01/07/22 16:13 PM - Last Modified 06/01/23 07:11 AM
Objective
Disabling the DNS security feature that is present inside an Anti-Spyware Profile.
Environment
- Palo Alto Networks Firewall
- PAN-OS 10.0 and above.
Procedure
- On the GUI, go to the Anti-Spyware profile (GUI: Objects > Security Profile > Anti-Spyware Profile > (name).
- Go to DNS Policies and set all Policy Actions as "allow" and all Packet Captures as "disable".
- Set the Log Severity for all categories to "none"
- Remove all DNS Domain/FQDN Allow List entries in the DNS Exceptions tab
- Commit the configuration.
Additional Information
On PAN-OS versions lower than 10.0, instead of "DNS Policies" it is named as "DNS Signatures > Policies and Settings".
Administrator’s Guide: Enable DNS Security