Anti-Spyware - DNS Sinkhole - Interpreting BPA Checks
This video provides information about the DNS Sinkhole check and how it will behave when a machine accesses a malicious domain.
The DNS Sinkhole feature enables the ability to identify the compromised or infected host machines that are accessing malicious domains. The best practice assessment check ensures DNS sinkhole and packet capture is enabled on the Anti-Spyware profile.
For more information on DNS Sinkhole, please review the following articles:
DNS Sinkholing (TechDocs - PAN-OS Administrator's Guide)
https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/threat-prevention/use-dns-queries-to-identify-infected-hosts-on-the-network/dns-sinkholing
How To Configure DNS Sinkhole
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGECA0
Comments
Post a Comment