Hi, Just confirm you can ping your DNS servers from the Palo through the CLI. Take few FQDN and try to see if you are getting a resolution, not from the Palo device, just use different PC. What PAN-OS are you running? After 6.1.x you can change refresh time to 600 seconds instead of 1800. If the device fails to get FQDN info during a refresh period, the firewall will not retry immediately. The firewall will wait for the new refresh period time. > configure # set deviceconfig system fqdn-refresh-time <600-14399> # commit More info here: https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-FQDN-Refresh-Timers/ta-p/55533 For your logs errors check this article: https://live.paloaltonetworks.com/t5/Management-Articles/Log-Collector-Setting-Does-Not-Clear-on-the-Palo-Alto-Networks/ta-p/55826 Thx, Myky
... View more