Okay, I have to get this off my chest. We've been running Prisma Access for about 18 months now, and overall it’s been solid for securing remote users. But I keep hitting a wall with DNS Security. It feels like the most inconsistent part of our deployment, and it's starting to drive our security team (and me!) a bit nuts.
Here’s what we’re seeing:
* **Intermittent filtering:** Policies for blocking malicious or unwanted domains don’t seem to apply uniformly. Some users get blocked, others don’t, with no clear pattern. It makes user onboarding confusing when we can't guarantee the same security posture for everyone.
* **Logging gaps:** The DNS Security logs in Cortex Hub are useful... when they're there. We've had scenarios where a user reported being blocked on a phishing test site, but we couldn't find the corresponding allow/deny event. Troubleshooting without logs is a nightmare.
* **Slow threat updates?** This one is anecdotal, but we've tested with newly registered malicious domains (from our threat intel feeds) and Prisma Access DNS took noticeably longer to categorize and block them compared to our old on-prem DNS layer.
I set up a comparison spreadsheet to track these inconsistencies against another vendor we tested, and the delta in reliability was eye-opening.
I'm a huge fan of the SASE vision and love how Prisma Access simplifies the network stack, but this one module feels underbaked. It's become the weak link that we have to work around.
Is anyone else experiencing this? Have you found specific tuning tips or configuration workarounds that made DNS Security more reliable for you? I'd love to compare notes and maybe build a shared checklist for best practices.
Keep building!