Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy
A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall itself can resolve DNS queries for internal and external resources. Which configuration setting is required on the firewall?
- ADNS Proxy Object
- BVirtual Router DNS Proxy
- CStatic DNS Servers
- DService Route Configuration
Show answer & explanationAnswer & explanation
Correct answer: C. Static DNS Servers
To allow the firewall itself to resolve DNS queries (e.g., for FQDN objects, URL categories, or updates), you must configure static DNS servers under Device > Setup > Services > DNS. This tells the firewall where to send its own DNS requests.
Why the other options are wrong
- A. A DNS Proxy Object is used to forward DNS queries from internal clients through the firewall, not for the firewall's own resolution.
- B. Virtual Router DNS Proxy is not a standard configuration element for the firewall's own DNS resolution; virtual routers handle routing.
- D. Service Route Configuration defines the egress interface for management services, but doesn't specify the DNS servers to use.
Static DNS Servers (Firewall)
Static DNS Servers configured on a Palo Alto Networks firewall (under Device > Setup > Services > DNS) are used by the firewall itself to resolve hostnames for updates, FQDN objects, and other internal operations.
- Used by the firewall for its own DNS queries.
- Essential for FQDN objects and dynamic updates.
- Configured under Device > Setup > Services > DNS.
Memory trick: The 'Static DNS Servers' are the firewall's own phonebook to the internet.