DNS Security

Showing results for 
Show  only  | Search instead for 
Did you mean: 

DNS Security

L1 Bithead



We are getting warning message (Warning: No valid DNS Security License) when we commit every time. currently we are using PAN OS 9.0.5. Is it possible to disable this warning message.



Logesh S.


L2 Linker

For me those settings worked: PanOS 10.1.2:



I've copied these settings on 10.1.3 and it still gives me the bloody warning 😥

I had the same problem when upgrading from 9.1.11 to 10.0.7. I found out what "botnet-domains" were by looking at the CLI's "set" commands: SSH into Palo Alto device > then enter this:

set cli pager off

set cli terminal width 500

set cli scripting-mode on

set cli config-output-format set




To get rid of the missing DNS license warning, you have to set allow/disable not only in the "default-paloalto-dns" line, but also on all other lines below "DNS Security" in Palo Alto's GUI.



Hi JH123, I had all the bottom ones set the same as you, once i changed the default-paloalto-dns  to allow and disable, my warning has also now gone. Thank you 🙂

L2 Linker

So effectively Palo Alto moved the sinkhole feature to the DNS security license? It was previously in the threat prevention license.

That and forcing us to the new unnecessary advanced url filtering license... this is really concerning.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!