AWS Partner Network (APN) Blog

Enhance DNS protection with Palo Alto Networks on Amazon Route 53 DNS Firewall

By: Anthony Smith, Sr. Security Partner Solutions Architect – AWS
By: Rizwan Mushtaq, Principal Solutions Architect – AWS
By: Ashmeet Singh, Sr. Customer Solutions Manager – AWS
By: Adhish Bhobe, Principal Product Manager – AWS
By: Arun Kumar, Director of Product Management, CDSS – Palo Alto Networks

Palo Alto Networks Logo
Palo Alto Networks
Palo Alto Networks Connect Button

Amazon Route 53 Resolver DNS Firewall now integrates Palo Alto Networks Advanced DNS Security to protect your DNS infrastructure. Because DNS queries are fundamental to how applications communicate, protecting them at the resolver gives security teams a powerful, centralized control point for safeguarding cloud traffic. This integration delivers comprehensive DNS threat protection that is effective and operationally straightforward to deploy across your cloud environments.

Palo Alto Networks, an AWS Partner Network (APN) partner, detects DNS-based threats such as command and control and fast flux. Palo Alto Networks Advanced DNS Security integrates with Amazon Route 53 Resolver DNS Firewall, delivering these threat-intelligence categories as DNS Firewall rules so you can enforce them with the availability and low latency of Amazon Web Services (AWS). By integrating Palo Alto Networks Advanced DNS Security with Route 53 Resolver DNS Firewall, security administrators can enforce trusted DNS threat protections across their Amazon Virtual Private Cloud (Amazon VPC) resources without deploying or managing additional infrastructure.

This post explores how the integration works, the threat coverage it adds on top of built-in DNS Firewall protections, and how security teams can extend that coverage across accounts, virtual private clouds (VPCs), and hybrid environments. Whether you’re securing a multi-account cloud environment or extending protections to hybrid-cloud traffic, this integration helps security teams deploy comprehensive DNS threat coverage faster and at scale.

Solution overview

Palo Alto Networks Advanced DNS Security is available directly from the Route 53 DNS Firewall console under the Advanced rule tier, with usage-based pricing and activation completing within 2 minutes—requiring no additional infrastructure. The integration operates through DNS Firewall rule groups, which are containers of one or more rules that can be associated with multiple VPCs and shared across accounts.

Each rule within a group specifies a security category, query type, and enforcement action, either BLOCK to deny resolution or ALERT to log without blocking. Rules are evaluated by configurable priority ordering within a group, giving administrators fine-grained control over how different threat types are handled.

A single rule group can protect any number of VPCs, and multi-account environments benefit from three sharing mechanisms: AWS Resource Access Manager (AWS RAM) for specific accounts or organizational units, Amazon Route 53 Profiles for consistent DNS configurations, and AWS Firewall Manager for centralized policy enforcement. AWS License Manager distributes subscriptions in bulk to an entire organization, specific organizational units (OUs), or individual accounts, with automatic licensing for newly added accounts.

How Palo Alto Networks Advanced DNS Security works with Amazon Route 53 DNS Firewall

By integrating Palo Alto Networks Advanced DNS Security with Route 53 DNS Firewall, organizations can enforce DNS threat protections across multiple traffic paths. As shown in the following demo, DNS Firewall rules with Palo Alto Networks security categories govern DNS query traffic from:

  • Amazon VPC traffic — Protecting workloads within your cloud environment
  • Hybrid-cloud traffic — Forwarded through Route 53 Resolver endpoints

The integration delivers more than 30 DNS threat detections from Palo Alto Networks—including fast flux protection, DNS hijacking protection, DNS rebinding protection, domain generation algorithm (DGA) detection, and newly registered domain identification—across the following use cases.

Cloud infrastructure DNS protection

Enforce Palo Alto Networks’ DNS threat protections directly on VPCs through DNS Firewall rules, with no need to deploy separate firewalls across multiple VPCs or AWS accounts. This removes the operational overhead of per-VPC firewall configurations while keeping coverage consistent. You can subscribe one time and share that subscription across multiple accounts or your entire organization using AWS License Manager.

Hybrid-cloud security operations

For on-premises or remote environments, DNS query traffic can be forwarded using Route 53 inbound endpoints, giving security operations center (SOC) teams unified DNS filtering and centralized logging across both AWS and hybrid traffic.

Centralized observability

Gain centralized observability across VPC and hybrid environments through log delivery via Amazon S3, Amazon Data Firehose, or Amazon CloudWatch Log Groups. Combined with AWS Security Hub, teams receive consolidated alerts and findings for faster detection and response.

Compliance and threat intelligence

Palo Alto Networks automatically updates its security categories and detection models, propagating changes to DNS Firewall with no customer intervention, keeping the latest threat intelligence applied to your DNS queries and streamlining compliance reporting.

Taken together, these use cases converge on a single enforcement point for DNS threat protection. The following demo illustrates how this comes together end to end, with visibility and control centralized through Amazon CloudWatch and AWS Security Hub.

Figure 1: How DNS query traffic from VPCs and hybrid environments is enforced through DNS Firewall rules with Palo Alto Networks threat intelligence

Figure 1: How DNS query traffic from VPCs and hybrid environments is enforced through DNS Firewall rules with Palo Alto Networks threat intelligence

Monitoring and insights

After the solution is deployed, monitor your DNS security posture through:

  1. AWS Security Hub — Security findings for blocked and alerted queries
  2. Amazon Route 53 Resolver query logs — Viewable and storable using S3 buckets, Amazon Data Firehose, or CloudWatch log groups

Cleanup and cost considerations

This solution incurs costs for the AWS and Palo Alto Networks services involved, priced as part of the existing DNS Firewall Advanced tier. You pay an hourly rate for each rule group containing one or more Palo Alto Networks rules associated with a VPC. During preview, the Palo Alto Networks subscription in AWS Marketplace is free and not charged; only DNS Firewall Advanced charges apply.

To avoid unnecessary charges:

  • Disassociate rule groups from VPCs and delete DNS Firewall rules containing Palo Alto Networks security categories. Charges continue until all Palo Alto Networks rules are removed, so clean up before or after unsubscribing.
  • Remove any license distributions configured through AWS License Manager.

Conclusion

Integrating Palo Alto Networks Advanced DNS Security with Amazon Route 53 Resolver DNS Firewall delivers comprehensive DNS threat protection without operational complexity. You’ll get streamlined deployment from the DNS Firewall console, automated threat-intelligence updates, and centralized multi-account management along with the performance you expect from Amazon Route 53 Resolver DNS Firewall, augmented with the latest threat intelligence from Palo Alto Networks.

To get started with Palo Alto Networks Advanced DNS Security, subscribe on the DNS Firewall console or in AWS Marketplace. For a step-by-step guide, visit Subscribe to Palo Alto Networks Advanced DNS Security. Use Palo Alto Networks’ documentation and the Amazon Route 53 Developer Guide to accelerate your deployment.

Connect with Palo-Alto-Networks


Palo Alto Networks – AWS Partner Spotlight

Palo Alto Networks is an AWS Security Competency Partner that helps organizations strengthen their security posture across cloud and hybrid environments—protecting against advanced threats, securing network infrastructure, and maintaining compliance to stay ahead of evolving adversaries.

Contact Palo Alto Networks | Partner Overview | AWS Marketplace