DNS Security

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

DNS Security

L1 Bithead

Hi, 

 

We are getting warning message (Warning: No valid DNS Security License) when we commit every time. currently we are using PAN OS 9.0.5. Is it possible to disable this warning message.

 

Regards,

Logesh S.

24 REPLIES 24

L2 Linker

RPBagiyev,

See my post from 7/13 above.  Those cli commands is what worked for me and TAC confirmed it is a good work around until they get a fix in.  

Hi Jesseivens,

 

In configure mode when I tab after delete shared there's no profiles command. Capture in attachment.Capture.JPG

L2 Linker

Ahh, that is because mine is a "shared" profile in Panorama.  In the firewall it should be like this.

delete profiles spyware "PROFILE-NAME" botnet-domains lists default-paloalto-dns
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-cc
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-ddns
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-grayware
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-malware
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-parked
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-phishing
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-proxy
delete profiles spyware "PROFILE-NAME" botnet-domains dns-security-categories pan-dns-sec-recent

Dear Jesseivens,

 

After typing these commands warnings are reduced but some remained. Still I got these warnings.

Thank you for the help.

Does anything DNS relates still show under the profile?  If so, I would keep removing them.  

show profiles spyware "PROFILE-NAME"

L2 Linker

For me those settings worked: PanOS 10.1.2:

Antispy.png

 

I've copied these settings on 10.1.3 and it still gives me the bloody warning 😥

I had the same problem when upgrading from 9.1.11 to 10.0.7. I found out what "botnet-domains" were by looking at the CLI's "set" commands: SSH into Palo Alto device > then enter this:

set cli pager off

set cli terminal width 500

set cli scripting-mode on

set cli config-output-format set

configure

show

 

To get rid of the missing DNS license warning, you have to set allow/disable not only in the "default-paloalto-dns" line, but also on all other lines below "DNS Security" in Palo Alto's GUI.

 

GUI.png

Hi JH123, I had all the bottom ones set the same as you, once i changed the default-paloalto-dns  to allow and disable, my warning has also now gone. Thank you 🙂

L2 Linker

So effectively Palo Alto moved the sinkhole feature to the DNS security license? It was previously in the threat prevention license.

That and forcing us to the new unnecessary advanced url filtering license... this is really concerning.

  • 24890 Views
  • 24 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!