Natively enforce Palo Alto Networks Advanced DNS Security on Amazon Route 53 Resolver DNS Firewall. Secure VPC and hybrid traffic against 30+ sophisticated threat dimensions with zero appliance overhead or architecture changes.
Manage Advanced DNS Security through the DNS Firewall section of the Amazon VPC console
Configuring Advanced DNS Security on Route 53 DNS Firewall involves four steps:
Subscribe to Advanced DNS Security through the DNS Firewall console or AWS Marketplace.
Create DNS Firewall rules by selecting Palo Alto Networks Advanced DNS security categories and specifying actions.
Associate rule groups with VPCs to enforce DNS threat protections across your organization.
Monitor DNS query activity through AWS CloudWatch metrics and Security Hub findings.
Product Overview
Palo Alto Networks Advanced DNS Security (ADNS) for Amazon Route 53 Resolver DNS Firewall bridges the gap between cloud infrastructure and elite network protection. This native integration injects Palo Alto Networks' industry-leading threat protection directly into the AWS core network plane. Security administrators can now seamlessly govern DNS query traffic originating from Amazon VPCs and hybrid cloud networks using trusted, enterprise-grade threat signatures and behavioral detection models - all configured directly within the native AWS console.
This integrated offering combines the ultra-low latency, native enforcement, and high availability of the Route 53 VPC Resolver with the real-time protection from ADNS. Through an embedded procurement experience, organizations can subscribe and instantly apply partner-managed advanced protections right where the traffic flows.
Comprehensive, Industry-Leading Threat Prevention
Security rules can be built to selectively BLOCK or ALERT against highly targeted threat categories, including:
Command and Control (C2) and Malware: Halts malicious data exfiltration and phone-home vectors.
Advanced Exploit Tactics: Real-time analysis catches fast-flux domains, proxy avoidance, dynamic DNS abuse, and DNS rebinding.
Keep your visibility centralized. All blocked and alerted query events map directly into your native cloud ecosystem - streaming logs automatically to Amazon CloudWatch metrics and AWS Security Hub.
Highlights
Seamless Native Integration: Manage ADNS through the DNS Firewall section of the Amazon VPC console.
Unified Control Console: Subscribe, configure rule categories, and set actions inside the AWS console.
Comprehensive Coverage with Precision AI: Block techniques like fast-flux, Advanced DGA, DNS Tunneling in real-time to stop sophisticated DNS threats.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing bills on a single usage-based dimension: Advanced DNS Security Usage Hours, where 1 unit equals 1 usage hour. You pay only for the hours you use, so cost scales directly with how long the service runs. There are no tiers, instance sizes, or separate add-ons to choose between. As a Free Preview, this offering lets you try the DNS security capability without upfront commitment. Your total is simply the number of usage hours consumed during the billing period.
Top-of-mind questions for buyers
What counts as one usage hour for billing?
One usage hour equals one hour that the Advanced DNS Security service runs against your Amazon Route 53 Resolver DNS Firewall. Each hour the service is active counts as one unit. The meter tracks active running time, not the number of DNS queries inspected.
Am I charged when the service is not actively running?
Charges accrue per usage hour while the service runs. Hours during which the service is not active do not add to your total. Your bill reflects only the hours the service was running during the billing period, so cost tracks active runtime directly.
What DNS protection does this usage cover?
The service inspects DNS queries and responses in real time to block command-and-control activity, malware distribution, domain hijacking, and data theft attempts. It uses machine learning and threat intelligence to detect evolving threats. This coverage is included in the usage hours you pay for.
www.paloaltonetworks.com+1
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Thank you for participating in the Public Preview of Palo Alto Networks Advanced DNS Security (ADNS) for Amazon Route 53 Resolver DNS Firewall.
During this public preview phase, the product is offered to customers entirely free of charge. Because this is a preview release intended for testing and evaluation purposes, official enterprise phone or web support portals (Palo Alto Networks Customer Support Portal - CSP) are not active for this specific integration.
How to Contact Support
Support for this preview product is limited exclusively to email communication. If you encounter setup queries, anomalies, false positives, or behavior issues, please reach out to our dedicated engineering and product team directly:
Our product and engineering teams actively monitor this inbox. While we do not have strict contractual Service Level Agreements (SLAs) or resolution time guarantees during the public preview phase, we will make every effort to review your submission and respond to all email inquiries as soon as possible.
When submitting an issue, please include the following to help us expedite your request:
A description of the observed behavior or threat category triggered.
The AWS Region(s) where the Route 53 Resolver DNS Firewall is currently deployed.
Relevant sanitized log snippets from Amazon CloudWatch or your Amazon S3 query logs, if applicable.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
F5 Distributed Cloud Services, powered by F5 AI Data Fabric, enables users to deploy, connect, secure and operate applications across public, private, network and edge clouds.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.