Anti-Spyware DNS Sinkhole BPA Checks


Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Printer Friendly Page
Retired Member
Did you find this article helpful? Yes No
No ratings

Anti-Spyware - DNS Sinkhole - Interpreting BPA Checks - Objects



This video provides information about the DNS Sinkhole check and how it will behave when a machine accesses a malicious domain.


The DNS Sinkhole feature enables the ability to identify the compromised or infected host machines that are accessing malicious domains. The best practice assessment check ensures DNS sinkhole and packet capture is enabled on the Anti-Spyware profile.


For more information on DNS Sinkhole, please review the following articles:

DNS Sinkholing (TechDocs - PAN-OS Administrator's Guide)

How To Configure DNS Sinkhole 


For additional resources regarding BPA, visit our LIVEcommunity BPA tool page.
View videos regarding BPA Network best practice checks.
View videos regarding BPA Policies best practice checks.
View videos regarding BPA Objects best practice checks.
View videos regarding BPA Devices best practice checks.
You may also view other BPA video playlist on the LIVEcommunity YouTube channel.

Tags (5)
Register or Sign-in
Version history
Last update:
‎07-07-2020 12:59 PM
Updated by: