6.5 Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use

Information

Enable passive DNS monitoring within all anti-spyware profiles in use.
Rationale:
Enabling passive DNS monitoring improves PAN's threat prevention and threat intelligence capabilities. This is performed without source information delivered to PAN to ensure sensitive DNS information of the organization is not compromised.

Solution

Navigate to Objects > Security Profiles > Anti-Spyware > Anti-Spyware profile > DNS signatures.
For each anti-spyware profile in use, set the Enable Passive DNS Monitoring box under the DNS Signatures tab to be checked.
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/1664

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(4), CSCv6|8.5, CSCv6|8.6

Plugin: Palo_Alto

Control ID: b81b5cfca6329caa79da9a45f77ad59442b5e86fd90fd25ae0028d9a06ac74df