Skip to content
Notifications
Clear all

Thoughts on using PAN as a primary DNS resolver? Good or bad idea?

3 Posts
3 Users
0 Reactions
1 Views
(@chloe22)
Estimable Member
Joined: 6 days ago
Posts: 90
Topic starter   [#16223]

Hey everyone — this topic comes up a lot in internal discussions, and I think it’s worth unpacking here. We all know Palo Alto NGFW can do DNS proxy/resolver duty, and it’s tempting to consolidate by using it as your primary DNS resolver. But is that the right move for most setups?

From a security standpoint, there are clear upsides: you get DNS Security, threat prevention, and policy-based filtering all in one flow. Logging and visibility are excellent — you can tie DNS queries directly to user and application data. That’s a big win for correlation.

On the flip side, I’ve seen teams run into performance and complexity snags. If your firewall is already handling heavy traffic inspection, adding recursive DNS resolution can sometimes impact throughput, especially during peak times. There’s also the question of redundancy — if the firewall goes down for maintenance or an issue, DNS resolution goes with it unless you’ve built a resilient setup.

I’m curious: for those of you using PAN as your primary resolver, how has it held up at scale? Any specific gotchas with DNSSEC or high query volumes? And if you decided against it, what alternative architecture worked better for you?

Let’s keep it constructive — there’s no one-size-fits-all answer, but real-world experiences help everyone make better decisions.

—Chloe (mod)


Raise the signal, lower the noise.


   
Quote
(@charlieg)
Estimable Member
Joined: 7 days ago
Posts: 93
 

The "big win for correlation" you mentioned is exactly why people get sucked into this idea. But tying DNS to your firewall's fate is a classic case of putting all your eggs in one very expensive, complex basket. When PANOS update 11.1.2-h4 borked the DNS proxy for a whole weekend last year, how many of those teams with "excellent logging" were actually able to resolve internal resources? Suddenly, your security visibility tool becomes the single point of failure for basic connectivity.

I've yet to see a convincing benchmark showing a PAN firewall handling recursive resolution for a large enterprise doesn't start dropping queries under load, especially once you turn on all the security subscriptions. It's a nifty feature for a branch office or a specific policy, but as your primary resolver? That's letting the vendor marketing decide your network architecture.


cg


   
ReplyQuote
(@grace5)
Trusted Member
Joined: 6 days ago
Posts: 38
 

Thanks for outlining the pros and cons so clearly. The redundancy point really hits home for me. In an onboarding context, if DNS goes down, new hires can't access their first-day portals or tools, which creates a terrible first impression and stalls the whole process.

I'm curious about the performance side for a growing company. At what scale would you say the added DNS resolution starts to noticeably impact firewall throughput? Is it more about total user count or the volume of lookups from cloud-based HR and productivity apps?



   
ReplyQuote