Threat Prevention has two modes:
- Background (allows the traffic to pass until classified)
- Hold (will not allow traffic to pass until classified)
If you were to hold a DNS request, the end user would experience a delay while we do a lookup to ThreatCloud.
This does not take long (and we cache the result), but in this case, it appears you are running in Background Mode (believe this is the default) and the DNS request/response completes before this lookup completes.
This is expected behavior.
You can change to Hold mode as shown here, though it will likely impact end user experience.
