Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy

A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall itself can resolve DNS queries for internal and external resources. Which configuration setting is required on the firewall?

  1. ADNS Proxy Object
  2. BVirtual Router DNS Proxy
  3. CStatic DNS Servers
  4. DService Route Configuration
Show answer & explanation

Correct answer: C. Static DNS Servers

To allow the firewall itself to resolve DNS queries (e.g., for FQDN objects, URL categories, or updates), you must configure static DNS servers under Device > Setup > Services > DNS. This tells the firewall where to send its own DNS requests.

Why the other options are wrong

  • A. A DNS Proxy Object is used to forward DNS queries from internal clients through the firewall, not for the firewall's own resolution.
  • B. Virtual Router DNS Proxy is not a standard configuration element for the firewall's own DNS resolution; virtual routers handle routing.
  • D. Service Route Configuration defines the egress interface for management services, but doesn't specify the DNS servers to use.

Static DNS Servers (Firewall)

Static DNS Servers configured on a Palo Alto Networks firewall (under Device > Setup > Services > DNS) are used by the firewall itself to resolve hostnames for updates, FQDN objects, and other internal operations.

  • Used by the firewall for its own DNS queries.
  • Essential for FQDN objects and dynamic updates.
  • Configured under Device > Setup > Services > DNS.

Memory trick: The 'Static DNS Servers' are the firewall's own phonebook to the internet.

More Deploy and Configure questions