<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Valid DNS Security License - Resolved in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/532185#M109719</link>
    <description>&lt;P&gt;Great, that works, thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 24 Feb 2023 15:00:30 GMT</pubDate>
    <dc:creator>daniel337KPS</dc:creator>
    <dc:date>2023-02-24T15:00:30Z</dc:date>
    <item>
      <title>No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/512415#M106480</link>
      <description>&lt;P&gt;We did a trial of DNS Security, after its expiration pushes from Panorama failed with warning "No Valid DNS Security License" Did a fair bit of searching, only real suggestion was here, that said to set all DNS Policies to Allow, that did not resolve the warning. Tried setting DNS Signatures to Default, still same commit warning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Poking around CLI, I was able to delete all the botnet-domains in our Spyware profile, commit and push with ZERO warnings; this successfully removed the DNS Security warnings. Hallelujah!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've not been able to find this anywhere, and so far Support doesn't seem to know about it either; their suggestion was what I found (set all to allow) that does not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Before:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;admin@Panorama# show shared profiles spyware "Default Anti-Spyware"&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical action reset-both &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical severity critical&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical packet-capture single-packet&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high action reset-both &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high severity high&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high packet-capture single-packet&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium action alert &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium severity medium&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium packet-capture disable&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low action alert &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low severity low&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low packet-capture disable&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains lists default-paloalto-dns action allow &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains lists default-paloalto-dns packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-adtracking log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-adtracking action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-adtracking packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-cc log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-cc action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-cc packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-ddns log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-ddns action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-ddns packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-grayware log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-grayware action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-grayware packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-malware log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-malware action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-malware packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-parked log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-parked action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-parked packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-phishing log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-phishing action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-phishing packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-proxy log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-proxy action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-proxy packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-recent log-level default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-recent action allow&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains dns-security-categories pan-dns-sec-recent packet-capture disable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains sinkhole ipv4-address 127.0.0.1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains sinkhole ipv6-address ::1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set shared profiles spyware "Default Anti-Spyware" botnet-domains threat-exception&lt;/EM&gt; &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" threat-exception 14978 action default&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;After:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;admin@Panorama# delete shared profiles spyware "Default Anti-Spyware" botnet-domains &lt;BR /&gt;&lt;BR /&gt;admin@Panorama# show shared profiles spyware "Default Anti-Spyware"&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical action reset-both &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical severity critical&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-critical packet-capture single-packet&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high action reset-both &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high severity high&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-high packet-capture single-packet&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium action alert &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium severity medium&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-medium packet-capture disable&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low action alert &lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low severity low&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low threat-name any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low category any&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" rules simple-low packet-capture disable&lt;BR /&gt;set shared profiles spyware "Default Anti-Spyware" threat-exception 14978 action default&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 23:29:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/512415#M106480</guid>
      <dc:creator>SteveBrown808</dc:creator>
      <dc:date>2022-08-19T23:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/512522#M106497</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231568"&gt;@SteveBrown808&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interesting finding. &lt;BR /&gt;Allow with packet capture disable is the default configuration. Similar to any other part of PAN XML config file, if anything is not explicetly mentioned in the config, firewall will apply the default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However if you set this configuration to something else or just explicetly set it to allow, this will still be part of the configuration file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like the DNS license check is probably only checking if botnet-domains is refered by the configuration and not what action is applied.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 11:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/512522#M106497</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-22T11:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/531624#M109634</link>
      <description>&lt;P&gt;I found the solution to the &lt;STRONG&gt;"&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;No Valid DNS Security License"&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;error caused by the Anti-Spyware profile. In addition to changing the POLICY ACTION to &lt;STRONG&gt;allow&lt;/STRONG&gt; and PACKET CAPTURE to &lt;STRONG&gt;disable&lt;/STRONG&gt;, you need to change the LOG SEVERITY to &lt;STRONG&gt;none&lt;/STRONG&gt;. I hope this helps someone. (This worked successfully on PAN-OS 10.2.2 &amp;amp; 10.2.3-h2)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Palo-Alto-Anti-Spyware-Fix-DNS-Error.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48070i513FC9011BBBFC90/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Palo-Alto-Anti-Spyware-Fix-DNS-Error.png" alt="Palo-Alto-Anti-Spyware-Fix-DNS-Error.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 22:00:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/531624#M109634</guid>
      <dc:creator>John_Pinegar</dc:creator>
      <dc:date>2023-02-17T22:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/532185#M109719</link>
      <description>&lt;P&gt;Great, that works, thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 15:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/532185#M109719</guid>
      <dc:creator>daniel337KPS</dc:creator>
      <dc:date>2023-02-24T15:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/533127#M109845</link>
      <description>&lt;P&gt;Thank you, it works.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 11:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/533127#M109845</guid>
      <dc:creator>Mohamed_Ibrahim</dc:creator>
      <dc:date>2023-03-03T11:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/554885#M112727</link>
      <description>&lt;P&gt;I don't feel the above solution is the complete solution. In actuality you could leave all that as is, and it doesn't matter if you created a new Anti-spyware profile or not. You can't delete the default or strict profiles or change them. So what matters is the settings located under Policies. These policies decide whether the Objects within the Security Profiles for Anti-Spyware are used.&lt;BR /&gt;&lt;BR /&gt;With that said;&lt;BR /&gt;&lt;BR /&gt;If you go into Policies &amp;gt; Security&lt;BR /&gt;&lt;BR /&gt;And you check your settings there to make sure that you don't see the shield within any of your security policies under profile. If you see the shield then you are using one of the objects Anti-spyware policies.&lt;BR /&gt;&lt;BR /&gt;If you click on the Security Policy Rule &amp;gt; Actions &amp;gt; Profile Setting &amp;gt; Profile Type. Set this to none and the shield will be replaced with none. Commit your changes and the "No DNS Security License." will no longer plague you while committing.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 16:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/554885#M112727</guid>
      <dc:creator>JeffCalabrese</dc:creator>
      <dc:date>2023-08-23T16:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/582879#M116535</link>
      <description>&lt;P&gt;Hi Jeff may i know which shield you are exactly talking about? is it possible to share a screen shot tobe clear about what shield you are referring to ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 03:43:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/582879#M116535</guid>
      <dc:creator>mohammad_saqib+</dc:creator>
      <dc:date>2024-04-08T03:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/583338#M116608</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/621115605"&gt;@mohammad_saqib+&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He means the Security Profile icon, which is displayed as a protective shield icon in the Security Policy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1712820381366.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59000iEDFA222C57C5CF03/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1712820381366.png" alt="kiwi_0-1712820381366.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 07:28:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/583338#M116608</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-04-11T07:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: No Valid DNS Security License - Resolved</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/1229973#M124374</link>
      <description>&lt;P&gt;Thank you. That was exactly the information I was missing.&lt;/P&gt;</description>
      <pubDate>Sat, 24 May 2025 09:05:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-valid-dns-security-license-resolved/m-p/1229973#M124374</guid>
      <dc:creator>johannes4711</dc:creator>
      <dc:date>2025-05-24T09:05:01Z</dc:date>
    </item>
  </channel>
</rss>

