6.5 Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use

Information

Enable passive DNS monitoring within all anti-spyware profiles in use.

Rationale:

Enabling passive DNS monitoring improves PAN's threat prevention and threat intelligence capabilities. This is performed without source information delivered to PAN to ensure sensitive DNS information of the organization is not compromised.

Solution

Navigate to Device > Setup > Telemetry. Set Passive DNS Monitoring to enabled

Default Value:

Not Configured

References:

'What Information is Submitted to the Palo Alto Networks when Enabling the Passive DNS Feature' - https://live.paloaltonetworks.com/docs/DOC-7256

'PAN-OS Administrator's Guide 9.0 (English) - DNS Security' - https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/dns-security.html#

See Also

https://workbench.cisecurity.org/files/2692