<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Security in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/413978#M93032</link>
    <description>&lt;P&gt;How do you get rid of this warning on PANOS 10.0.6?&amp;nbsp; Where do you delete all botnet-domains ?&amp;nbsp; I guess I can just import them via minemeld anyway?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 19:11:16 GMT</pubDate>
    <dc:creator>ksauer507</dc:creator>
    <dc:date>2021-06-17T19:11:16Z</dc:date>
    <item>
      <title>DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330282#M83743</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are getting warning message (Warning: No valid DNS Security License) when we commit every time. currently we are using PAN OS 9.0.5. Is it possible to disable this warning message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Logesh S.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 13:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330282#M83743</guid>
      <dc:creator>Logesh</dc:creator>
      <dc:date>2020-05-28T13:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330299#M83746</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/68912"&gt;@Logesh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this time there's no way to suppress warning messages during commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fix the warning &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Or reach out to your local SE and have him add your vote to the existing feature request there is for this (FR ID: &lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;2689 - Suppress Warnings in Commit&lt;/SPAN&gt;&lt;/SPAN&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 28 May 2020 13:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330299#M83746</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-05-28T13:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330307#M83747</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&amp;nbsp;i will check the same.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 13:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330307#M83747</guid>
      <dc:creator>Logesh</dc:creator>
      <dc:date>2020-05-28T13:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330311#M83748</link>
      <description>&lt;P&gt;this means you enabled or changed the action on the 'palo alto networks dns security' option in DNS signatures of one or more of your spyware profiles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you should set it to 'allow' with no packetcapture if you do not have a license&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 13:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/330311#M83748</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-05-28T13:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/346890#M86558</link>
      <description>&lt;P&gt;You are THE MAN!&amp;nbsp; This answer should be marked as the solution.&amp;nbsp; I love clearing all commit errors.&amp;nbsp; It should be emphasized more in best practices.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 14:10:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/346890#M86558</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2020-09-04T14:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/386461#M90256</link>
      <description>&lt;P&gt;Just a quick update on this older topic that under PANOS 10.0.x, the DNS Sec license is now integrated in the policy and you can no longer make this change.&amp;nbsp; Additionally, you cannot change the built-in default policy either.&amp;nbsp; The kicker is that my Palo Alto account manager offered to sell me DNS Security licenses to get rid of the error and the TAC Engineer told me that its "cosmetic and just a warning" and to file a feature request through my account manager.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mlinsemier_0-1613595029976.png" style="width: 308px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29980iCD72A0577766217D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mlinsemier_0-1613595029976.png" alt="mlinsemier_0-1613595029976.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I love when my security team sends me messages every day asking why where are warnings in Panorama about security policies being committed with warnings.&amp;nbsp; Hopefully as more of us move towards 10.0.x Palo Alto will do something about this.&amp;nbsp; It frustrating as this option shouldn't be configurable if we don't have a license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 20:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/386461#M90256</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2021-02-17T20:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/394082#M91075</link>
      <description>&lt;P&gt;Hi Matt, I have the same in PANOS 10 I deleted that warning deleting all&amp;nbsp;&lt;SPAN&gt;botnet-domains, it works if you don't want use the sinkhole feature.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 23:24:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/394082#M91075</guid>
      <dc:creator>crodrigueze</dc:creator>
      <dc:date>2021-03-25T23:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/401395#M91693</link>
      <description>&lt;P&gt;So we need to have a license now to utilize SinkHole?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 20:04:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/401395#M91693</guid>
      <dc:creator>fpadmin</dc:creator>
      <dc:date>2021-04-22T20:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/405858#M92047</link>
      <description>&lt;P&gt;Can you clarify a bit on what you deleted and where so I can review?&amp;nbsp; I'm not sure where you are seeing botnet-domains.&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 21:22:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/405858#M92047</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2021-05-10T21:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/413978#M93032</link>
      <description>&lt;P&gt;How do you get rid of this warning on PANOS 10.0.6?&amp;nbsp; Where do you delete all botnet-domains ?&amp;nbsp; I guess I can just import them via minemeld anyway?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 19:11:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/413978#M93032</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2021-06-17T19:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/419097#M93752</link>
      <description>&lt;P&gt;I ran into this issue when I upgraded some VM-500s to 10.0.6.&amp;nbsp; I was able to clone the default spyware profile, which I named "default-no-dns-sec"&amp;nbsp; Then I went into CLI and issued the following commands to delete DNS specific items.&lt;/P&gt;&lt;P&gt;delete shared profiles spyware default-no-dns-sec botnet-domains lists default-paloalto-dns&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-cc&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-ddns&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-grayware&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-malware&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-parked&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-phishing&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-proxy&lt;BR /&gt;delete shared profiles spyware default-no-dns-sec botnet-domains dns-security-categories pan-dns-sec-recent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On this firewall I have not "production" traffic yet, so I was able to disable all policies.&amp;nbsp; I enabled 1 with this new profile and pushed from Panorama.&amp;nbsp; No issues with the commit and no more warning.&amp;nbsp; All policies and/or Security Profile Groups will need to be updated to completely solve this.&lt;/P&gt;&lt;P&gt;I do have a TAC case open, so I am waiting for confirmation from TAC on this.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 19:29:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/419097#M93752</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-07-13T19:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/419338#M93776</link>
      <description>&lt;P&gt;Thanks for the update on this and I'm interested to hear what TAC replies with now.&amp;nbsp; It's kind of ridiculous that this is something that has to be done manually.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 15:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/419338#M93776</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2021-07-14T15:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/419349#M93777</link>
      <description>&lt;P&gt;So far not much.&amp;nbsp; I am upgrading my PA3260s tonight from 9.1.9 to 10.0.6.&amp;nbsp; This is the same think I did on the VM500s.&amp;nbsp; I have also upgrade a VM100 and PA220, neither of which I had this problem.&amp;nbsp; Only issue was on the VM500s.&amp;nbsp; I ask TAC why this was and this is all I got back.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is a buggy behavior, I've been checking similar cases with the same issue, different platforms. Also on versions 10.0.5 and 10.0.6.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We don't have a root cause of the issue yet, but I'm glad the workaround worked for you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did do the workaround in Panorama on a shared profile, so it was only a 1 time change, since it is shared and I was able to push to all my different device groups at once.&amp;nbsp; I also took the opportunity change all policies to Security Profile Groups.&amp;nbsp; So if I need to change again, it is only a group change which affects all the policies that it is applied to.&amp;nbsp; Hoping that doesn't bite me down the road &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 15:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/419349#M93777</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-07-14T15:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/420334#M93866</link>
      <description>&lt;P&gt;Per my TAC case, &lt;SPAN&gt;Engineering had found that the issue is traced to a known issue PAN-164941 currently. The commits will retain the warnings but the commits will still go through and the issue will be resolved in Fixed Versions: 9.1.11, 10.0.8.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My work around posted removed the warnings and no further issues on any of my models.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 14:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/420334#M93866</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-07-19T14:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427484#M94613</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I commit changes in Palo Alto (Software Version 10.0.6) I got a lot of warnings (No Valid DNS Security License).&lt;/P&gt;&lt;P&gt;In Objects &amp;gt; Security Profiles &amp;gt; Anti-Spyware there are 2 predefined profiles: default and strict.&lt;/P&gt;&lt;P&gt;I cloned strict profile. Changed Action to allow under Signature Policies, changed Policy Action to allow under DNS Policies, changed Sinkhole IPv4 to IPv4 Loopback IP (127.0.0.1). I did these things at different times. But it didn't help. I still got these warnings and its annoying. Could you show me exact place what to do?&lt;/P&gt;&lt;P&gt;P.S. I don't have a DNS Security license.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 08:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427484#M94613</guid>
      <dc:creator>RPBagiyev</dc:creator>
      <dc:date>2021-08-18T08:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427503#M94618</link>
      <description>&lt;P&gt;RPBagiyev,&lt;/P&gt;&lt;P&gt;See my post from 7/13 above.&amp;nbsp; Those cli commands is what worked for me and TAC confirmed it is a good work around until they get a fix in.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 10:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427503#M94618</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-08-18T10:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427507#M94619</link>
      <description>&lt;P&gt;Hi Jesseivens,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In configure mode when I tab after delete shared there's no profiles command. Capture in attachment.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 401px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35755i7BC481338CBB222D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 10:57:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427507#M94619</guid>
      <dc:creator>RPBagiyev</dc:creator>
      <dc:date>2021-08-18T10:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427508#M94620</link>
      <description>&lt;P&gt;Ahh, that is because mine is a "shared" profile in Panorama.&amp;nbsp; In the firewall it should be like this.&lt;/P&gt;&lt;P&gt;delete profiles spyware "PROFILE-NAME" botnet-domains lists default-paloalto-dns&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-cc&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-ddns&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-grayware&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-malware&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-parked&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-phishing&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-proxy&lt;BR /&gt;delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-recent&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 11:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427508#M94620</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-08-18T11:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427511#M94621</link>
      <description>&lt;P&gt;Dear Jesseivens,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After typing these commands warnings are reduced but some remained. Still I got these warnings.&lt;/P&gt;&lt;P&gt;Thank you for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 11:53:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427511#M94621</guid>
      <dc:creator>RPBagiyev</dc:creator>
      <dc:date>2021-08-18T11:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427512#M94622</link>
      <description>&lt;P&gt;Does anything DNS relates still show under the profile?&amp;nbsp; If so, I would keep removing them.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show profiles spyware "PROFILE-NAME"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 12:05:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-security/m-p/427512#M94622</guid>
      <dc:creator>jesseivens</dc:creator>
      <dc:date>2021-08-18T12:05:42Z</dc:date>
    </item>
  </channel>
</rss>

