Overview
Manage Advanced DNS Security through the DNS Firewall section of the Amazon VPC console
Configuring Advanced DNS Security on Route 53 DNS Firewall involves four steps:
- Subscribe to Advanced DNS Security through the DNS Firewall console or AWS Marketplace.
- Create DNS Firewall rules by selecting Palo Alto Networks Advanced DNS security categories and specifying actions.
- Associate rule groups with VPCs to enforce DNS threat protections across your organization.
- Monitor DNS query activity through AWS CloudWatch metrics and Security Hub findings.
Product Overview
Palo Alto Networks Advanced DNS Security (ADNS) for Amazon Route 53 Resolver DNS Firewall bridges the gap between cloud infrastructure and elite network protection. This native integration injects Palo Alto Networks' industry-leading threat protection directly into the AWS core network plane. Security administrators can now seamlessly govern DNS query traffic originating from Amazon VPCs and hybrid cloud networks using trusted, enterprise-grade threat signatures and behavioral detection models - all configured directly within the native AWS console.
This integrated offering combines the ultra-low latency, native enforcement, and high availability of the Route 53 VPC Resolver with the real-time protection from ADNS. Through an embedded procurement experience, organizations can subscribe and instantly apply partner-managed advanced protections right where the traffic flows.
Comprehensive, Industry-Leading Threat Prevention
Security rules can be built to selectively BLOCK or ALERT against highly targeted threat categories, including:
- Command and Control (C2) and Malware: Halts malicious data exfiltration and phone-home vectors.
- Advanced Exploit Tactics: Real-time analysis catches fast-flux domains, proxy avoidance, dynamic DNS abuse, and DNS rebinding.
- Domain Abuse Categories: Proactive protection blocking newly registered domains (NRDs), domain squatting, parked domains, and grayware.
Native Analytics and Hybrid Network Security
Keep your visibility centralized. All blocked and alerted query events map directly into your native cloud ecosystem - streaming logs automatically to Amazon CloudWatch metrics and AWS Security Hub.
Highlights
- Seamless Native Integration: Manage ADNS through the DNS Firewall section of the Amazon VPC console.
- Unified Control Console: Subscribe, configure rule categories, and set actions inside the AWS console.
- Comprehensive Coverage with Precision AI: Block techniques like fast-flux, Advanced DGA, DNS Tunneling in real-time to stop sophisticated DNS threats.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
|---|---|
Advanced DNS Security Usage Hours (1 unit = 1 usage hour) | $0.30 |
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Product Support & Public Preview Guidelines
Thank you for participating in the Public Preview of Palo Alto Networks Advanced DNS Security (ADNS) for Amazon Route 53 Resolver DNS Firewall.
During this public preview phase, the product is offered to customers entirely free of charge. Because this is a preview release intended for testing and evaluation purposes, official enterprise phone or web support portals (Palo Alto Networks Customer Support Portal - CSP) are not active for this specific integration.
How to Contact Support
Support for this preview product is limited exclusively to email communication. If you encounter setup queries, anomalies, false positives, or behavior issues, please reach out to our dedicated engineering and product team directly:
- Support Email: adns-support@paloaltonetworks.com
Service Level Expectations
Our product and engineering teams actively monitor this inbox. While we do not have strict contractual Service Level Agreements (SLAs) or resolution time guarantees during the public preview phase, we will make every effort to review your submission and respond to all email inquiries as soon as possible.
When submitting an issue, please include the following to help us expedite your request:
- A description of the observed behavior or threat category triggered.
- The AWS Region(s) where the Route 53 Resolver DNS Firewall is currently deployed.
- Relevant sanitized log snippets from Amazon CloudWatch or your Amazon S3 query logs, if applicable.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
