DNS Sinkhole no Palo Alto na prática: TAG + DAG bloqueando o host automaticamente (sem commit)

DNS Sinkhole on Palo Alto is excellent for identifying endpoints trying to resolve malicious/C2 domains — but the real gain comes when you automate containment. In this video, I set up the lab and show the complete flow: Anti-Spyware DNS policy → Sinkhole → Log Forwarding setting TAG → Dynamic Address Group (DAG) → blocking policy, causing the host to automatically lose access when hitting a malicious domain. Licensing (practical view): you usually need Threat Prevention (Anti-Spyware). Depending on your environment/subscriptions, DNS Security can be added as a complement — and I show this in the video. Chapters 00:00 Intro 00:19 How DNS Sinkhole Works (basic) 01:34 Lab 02:40 Required Licensing 03:05 Security Profile → Anti-Spyware → DNS Policy 05:10 Creating the TAG for “infected” hosts 05:50 Log Forwarding: when threat = sinkhole → apply TAG 08:10 Creating the DAG based on the TAG 09:10 Applying the profile + log forwarding to the DNS rule 10:30 Blocking policy for the DAG (closing the loop) 12:10 Dynamic Updates 13:30 Test: host accesses known C2 domain 14:40 Host automatically loses internet (entered the DAG) 15:50 Validating the host within the DAG 16:30 Logs: traffic + threat 18:43 Unregister in the DAG to release the Host 19:40 Host gets internet back 19:55 Extra logs 22:50 Closing and questions If this content helped you in any way, please consider liking and sharing. The purpose of this channel is to help!

Palo Alto Firewall: How to Automate Bulk Configurations via CLI
▶︎

Palo Alto Firewall: How to Automate Bulk Configurations via CLI

How to Configure BGP on Palo Alto (2 Firewalls) + Route Table and Logs - 2026
▶︎

How to Configure BGP on Palo Alto (2 Firewalls) + Route Table and Logs - 2026

How I would start in Cyberpunk 2026 (If I could start over)
▶︎

How I would start in Cyberpunk 2026 (If I could start over)

Firewall from Scratch #4 SSL Decryption on Palo Alto with Windows AD CS CA in Practice
▶︎

Firewall from Scratch #4 SSL Decryption on Palo Alto with Windows AD CS CA in Practice

Curso de DevOps Do Zero ao Deploy | Aula Final: Cloud, AWS e Deploy Completo em Produção
▶︎

Curso de DevOps Do Zero ao Deploy | Aula Final: Cloud, AWS e Deploy Completo em Produção

APIs for Beginners - How to use an API (Full Course / Tutorial)
▶︎

APIs for Beginners - How to use an API (Full Course / Tutorial)

Palo Alto: Auto-blocking malicious IPs with Tags + Dynamic Address Groups (DAG)
▶︎

Palo Alto: Auto-blocking malicious IPs with Tags + Dynamic Address Groups (DAG)

DEUS ESTÁ TE CHAMANDO PARA UMA NOVA VIDA | Deive Leonardo 2026
▶︎

DEUS ESTÁ TE CHAMANDO PARA UMA NOVA VIDA | Deive Leonardo 2026

Pork Shot! A West Tunnel Exclusive Mini-Game - Hermitcraft 11 | Ep 24
▶︎

Pork Shot! A West Tunnel Exclusive Mini-Game - Hermitcraft 11 | Ep 24

n8n Course for Beginners – Build Complex Workflows & Master AI Integration
▶︎

n8n Course for Beginners – Build Complex Workflows & Master AI Integration

EMPIEZA EL JUEVES CON FE | HOY DIOS TE DA PROTECCIÓN Y PAZ PARA TU FAMILIA | PADRE FREDDY BUSTAMANTE
▶︎

EMPIEZA EL JUEVES CON FE | HOY DIOS TE DA PROTECCIÓN Y PAZ PARA TU FAMILIA | PADRE FREDDY BUSTAMANTE

11-06-26 Sukhmani Sahib Full Path | ਸੁਖਮਨੀ ਸਾਹਿਬ ਪਾਠ | Sukhmani Sahib Da Path | Fast Sukhmani
▶︎

11-06-26 Sukhmani Sahib Full Path | ਸੁਖਮਨੀ ਸਾਹਿਬ ਪਾਠ | Sukhmani Sahib Da Path | Fast Sukhmani

The Day Diego Maradona DIED - Rise, Fall, and Legend of D10S
▶︎

The Day Diego Maradona DIED - Rise, Fall, and Legend of D10S

OpenCode: Probablemente la mejor herramienta Open Source para programar
▶︎

OpenCode: Probablemente la mejor herramienta Open Source para programar

Elfenbeinküste – Ecuador Highlights | Gruppe E, FIFA WM 2026 | sportstudio
▶︎

Elfenbeinküste – Ecuador Highlights | Gruppe E, FIFA WM 2026 | sportstudio

Prisão de Deolane: Cabrini mostra os detalhes do esquema de lavagem de dinheiro
▶︎

Prisão de Deolane: Cabrini mostra os detalhes do esquema de lavagem de dinheiro

DNS Proxy in Palo Alto: automatic failover (Umbrella → 8.8.8.8)
▶︎

DNS Proxy in Palo Alto: automatic failover (Umbrella → 8.8.8.8)

SQL Course for Beginners [Full Course]
▶︎

SQL Course for Beginners [Full Course]

Listen and Feel the Peace | Tibetan Healing Sounds for Deep Meditation, Inner Peace & Soul Healing
▶︎

Listen and Feel the Peace | Tibetan Healing Sounds for Deep Meditation, Inner Peace & Soul Healing

I Became The Most FEARED WARLORD Of This Minecraft SMP
▶︎

I Became The Most FEARED WARLORD Of This Minecraft SMP