Enable DNS filtering to identify URLs during domain lookup
DNS filtering allows you to identify and block URLs based on category and reputation during domain lookup, providing an additional layer of security by preventing access to malicious or unwanted domains before connections are established.
DNS filtering is enabled by default in new access control policies. However, additional configurations may be required in order for this setting to take effect.
Before you begin
-
URL filtering using category and reputation must be licensed, enabled, and configured.
DNS filtering does not use these settings in the URLs tab: URL groups, URL objects, URL lists and feeds, and URLs entered into the "Enter URL" text box.
-
Refer to limitations at DNS filtering behavior for block actions.
Procedure
Step 1 | In your access control policy's advanced settings, select Enable reputation enforcement on DNS traffic. |
Step 2 | In the same policy, for each access control rule that has URL category and reputation blocking configured:
|
Step 3 | Save your changes. |
What to do next
If you are done making changes, Deploy configuration changes.