<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Security in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/262546#M568</link>
    <description>&lt;P&gt;I got the confirmation from Engineering that it is expected not to be able to delete default DNS options from GUI. You can use CLI. Fix for the warnings during commit is targeted to be released on 9.0.4&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 14:17:39 GMT</pubDate>
    <dc:creator>lcelinski</dc:creator>
    <dc:date>2019-05-29T14:17:39Z</dc:date>
    <item>
      <title>DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/257619#M542</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there any way to turn off the following information after commit on 9.0.1 with&amp;nbsp;&lt;SPAN&gt;Anti-Spyware Profile attached to Security Policy?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can't delete Palo Alto Networks DNS Security option from&amp;nbsp;Anti-Spyware Profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Warnings&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="x-form-element"&gt;&lt;DIV class=" x-form-display-field"&gt;&lt;UL&gt;&lt;LI&gt;Warning: No Valid DNS Security License&lt;/LI&gt;&lt;LI&gt;(Module: device)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lukasz&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 15 Apr 2019 14:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/257619#M542</guid>
      <dc:creator>lcelinski</dc:creator>
      <dc:date>2019-04-15T14:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/260679#M546</link>
      <description>&lt;P&gt;Try delete it from CLI:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;delete profiles spyware XXXXX botnet-domains lists default-paloalto-cloud&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 08:42:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/260679#M546</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2019-05-13T08:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/260683#M547</link>
      <description>&lt;P&gt;I opened a case and it was escalated&amp;nbsp;developers&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 09:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/260683#M547</guid>
      <dc:creator>lcelinski</dc:creator>
      <dc:date>2019-05-13T09:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/262545#M567</link>
      <description>&lt;P&gt;Thank you, this works for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can't delete it from the default anti-spyware profiles, so if you are using them the warning will appear everytime you commit.&lt;/P&gt;&lt;P&gt;I cloned both of them (default and strict). Then I delete that "default-paloalto-cloud" entry from these new profiles and to finish I ensured to change the defaults with the new ones in all the Profiles Groups, Security Policies, etc...&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 13:56:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/262545#M567</guid>
      <dc:creator>aritzposada</dc:creator>
      <dc:date>2019-05-29T13:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/262546#M568</link>
      <description>&lt;P&gt;I got the confirmation from Engineering that it is expected not to be able to delete default DNS options from GUI. You can use CLI. Fix for the warnings during commit is targeted to be released on 9.0.4&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 14:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/262546#M568</guid>
      <dc:creator>lcelinski</dc:creator>
      <dc:date>2019-05-29T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/267285#M574</link>
      <description>&lt;P&gt;I am trying to do this in Panoramma using the following command but get an error. The profile I am trying to delete it from is one I created and not a predefined one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;delete device-group [device-group] profiles spyware [spyware-profile] botnet-domains lists default-paloalto-cloud&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No object to delete in delete handler&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 10:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/267285#M574</guid>
      <dc:creator>rmarlow</dc:creator>
      <dc:date>2019-06-06T10:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/267286#M575</link>
      <description>&lt;P&gt;Hi Rmarlow,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible that this object is in use? Or maybe shared?&lt;BR /&gt;Try cloning this object and deleting the profile "default-paloalto-cloud". If this works, it may be because the original object is referenced.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 10:30:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/267286#M575</guid>
      <dc:creator>aritzposada</dc:creator>
      <dc:date>2019-06-06T10:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/267287#M576</link>
      <description>&lt;P&gt;Thanks for the quick response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at it again this profile was located in shared so I needed to use the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;delete shared profiles spyware [spyware-profile] botnet-domains lists default-paloalto-cloud&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 10:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/267287#M576</guid>
      <dc:creator>rmarlow</dc:creator>
      <dc:date>2019-06-06T10:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/279927#M615</link>
      <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it possible to share the command to delete the Antispyware profile&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 07:04:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/279927#M615</guid>
      <dc:creator>HemanthV</dc:creator>
      <dc:date>2019-07-30T07:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/419100#M1228</link>
      <description>&lt;P&gt;I ran into this issue when I upgraded some VM-500s to 10.0.6.&amp;nbsp; I was able to clone the default spyware profile, which I named "default-no-dns-sec"&amp;nbsp; Then I went into CLI and issued the following commands to delete DNS specific items.&lt;/P&gt;&lt;P&gt;delete shared profiles spyware default-no-dns-sec botnet-domains lists default-paloalto-dns&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-cc&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-ddns&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-grayware&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-malware&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-parked&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-phishing&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-proxy&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-recent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On this firewall I have not "production" traffic yet, so I was able to disable all policies.&amp;nbsp; I enabled 1 with this new profile and pushed from Panorama.&amp;nbsp; No issues with the commit and no more warning.&amp;nbsp; All policies and/or Security Profile Groups will need to be updated to completely solve this.&lt;/P&gt;&lt;P&gt;I do have a TAC case open, so I am waiting for confirmation from TAC on this.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 19:30:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/419100#M1228</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-07-13T19:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/432768#M1310</link>
      <description>&lt;P&gt;I think deleting the AntiSpyWare profile wouldn't be a great move. That will decrease your visibility. Try allowing an exception using the ID. You can do this from the Threat Monitor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 10:06:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/432768#M1310</guid>
      <dc:creator>Kryptonite</dc:creator>
      <dc:date>2021-09-09T10:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/432790#M1311</link>
      <description>&lt;P&gt;My comment above is only deleting the dns-sec from the profile, not removing the whole AntiSpyWare profile.&amp;nbsp; I am still using all the other functions of the AntiSpyWare profile.&amp;nbsp; Also my solution was confirmed to by TAC for a work around.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 12:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/dns-security/m-p/432790#M1311</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-09-09T12:09:47Z</dc:date>
    </item>
  </channel>
</rss>

