- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-24-2019 02:01 PM
In reading up on DNS Security I found that URL's provided for testing in the following document, Enabling DNS Security, do not accurately ensure DNS Security feature license is installed and configured. A very accurate indicator of this is that all of those URL's are adequately blocked on a firewall running PAN-OS 8.1.x due to the PAN-DB URL filtering policies most companies would have enabled.
Here is the suggested testing method from the above URL:
So this leads me to the questions...
BTW, @PANW - Why is the Oilrig signature default action "alert" instead of blocking it? Using a strict profile is pretty essential.
If you have a successful test plan for DNS Security implementation please comment.
Thanks!