Configure DNS Filtering rules using the Rules tab to customize security filtering and allowed domains across your sites and policies. The site option you select determines the policies available, selecting Global (All sites) provides global OneView policies, where selecting individual sites provides only site-level policies. Configuring access for a domain will include its subdomains, but configuring access for a subdomain will not include the entire domain.
Note: Global Administrators can manage global rules across OneView. Site Administrators can view all global rules and only manage site-specific rules.
CAUTION - Before configuring DNS rules, enter global exclusions for your internal domains to prevent them from being restricted. For more information, see Create DNS Filtering site exclusions in OneView.
Create DNS Filtering rule
- In the left navigation menu, click Monitor > DNS Filtering.
- In the top left, select the Rules tab.
- In the top right, click the Add Rule icon +.
- Enter a name for the DNS Rule.
- Select all or specify a OneView site.
- Global (All sites): Choose this option if your sites are managed using global policies.
- Individual site: Choose this option if your sites are managed using local site-level policies.
- Check the box for one or more policies. The options in this list depend on the site selection in step 5. If a policy you're looking for doesn't appear, make sure the correct site is selected or that all your policies don't already have a DNS rule assigned to them.
- Click Next to proceed to the Block List.
- Review and remove unwanted security categories. For more information, see Security categories.
- Enter or select domains, subdomains, top level domains, IP addresses, or Content categories to block and click Add.
CAUTION - Blocking content categories such as Technology may cause popular business domains to be stopped mistakenly.
- Click Next to proceed to the Allow List.
- Enter domains, subdomains, or IP addresses to allow and click Add. Once complete, click Next.
- Review the rule and click Save rule once complete.
Notes:
- The maximum number of DNS rules is 50 per site.
- The allow list and block list have a limit of 4000 domains.
- Each policy can only have one DNS rule applied.
- Use the Bulk upload feature to upload a .CSV file with a list of items to add to the block or allow list. Use separate CSV files for different domain types.
- Add domains to the allow list of your DNS rules if you require access to a blocked domain.
- If entering IP addresses, only the domains associated with the IP address are blocked or allowed.
Categories
The available security and content categories are listed below.
Security categories
Categories | Description |
New Domains | Domains that have been registered very recently. |
Newly Seen Domains | Domains that have recently been resolved for the first time. |
Anonymizer | Sites that allow attackers to hide their IP addresses. |
Brand Embedding | Embedding of external brand name. |
Command and Control & Botnet | Sites that are queried by compromised devices to exfiltrate information or potentially infect other devices in a network. |
Cryptomining | Sites that mine cryptocurrency by taking over the user's computing resources. |
DGA Domains | Domains detected as generated by algorithms seen in malware. |
DNS Tunneling | Domains with detected DNS tunneling activity. |
Domain Generation Algorithm | Domains detected as generated by algorithms seen in malware. |
Malware | Sites hosting malicious content and other compromised websites. |
Phishing | Domains that are known for stealing personal information. |
Private IP Address | Domains that resolve to private IP Addresses. |
Spam | Sites that are known for targeting users with unwanted sweepstakes, surveys, and advertisements. |
Spyware | Sites that are known to distribute or contain code that displays unwanted advertisements or gathers user information without the user's knowledge. |
Content categories
Confirm which category a domain belongs to by using the search domain categories field on the right.
Categories | Subcategories |
Adult Themes |
Adult Themes Nudity Pornography |
Blocked |
Child Abuse |
Business & Economy |
Business Economy & Finance |
CIPA |
Cipa Filter |
Education |
Education Educational Institutions Science Space & Astronomy |
Entertainment |
Arts Audio Streaming Cartoons & Anime Comic Books Entertainment Fine Art Gaming Home Video/DVD Humor Magazines Movies Music News & Media Paranormal Radio Television Video Streaming |
Gambling | Gambling |
Government & Politics |
Government Politics, Advocacy, and Government-Related |
Health |
Health & Fitness Sex Education |
Internet Communication |
Chat Forums Information Security Instant Messengers Internet Phone & VOIP Messaging P2P Personal Blogs Photo Sharing Webmail |
Job Search & Careers | Job Search & Careers |
Military & Weapons |
Military Weapons |
Miscellaneous |
Miscellaneous Redirect |
Questionable Content |
Deceptive Ads Drugs Hacking Militancy, Hate & Extremism Profanity Questionable Activities Unreliable Information |
Real Estate | Real Estate |
Religion | Religion |
Safe for Kids | Safe for Kids |
Shopping & Auctions |
Auctions & Marketplaces Coupons Ecommerce Shopping |
Social & Family |
N/A |
Society & Lifestyle |
Abortion Arts & Crafts Astrology Body Art Clothing Dating & Relationships Digital Postcards Fashion Food & Drink Hobbies & Interests Home & Garden Jewelry LGBTQ Lifestyle Lingerie & Bikini Parenting Pets Photography Professional Networking Sexuality Social Networks Swimsuits Tobacco |
Sports | Sports |
Technology |
APIs Content Servers File Sharing Information Technology News, Portal & Search Search Engines Technology Translator |
Travel | Travel |
Vehicles | Vehicles |
Violence |
Violence Weapons |
Weather | Weather |
Technology content category
We advise against blocking the technology content category as most of the domains for My Account and e-commerce activity are included in that category. If you are blocking this category, add these to the allow list:
Domain |
Subcategories |
avangate.net |
Technology |
assets.adobedtm.com |
Content Servers, Technology |
www.paypalobjects.com |
Content Servers, Technology |
static.criteo.net |
Technology |
api.airbrake.io |
Technology |
www.google-analytics.com |
Technology |
clientservices.googleapis.com |
Technology |
js.authorize.net |
Technology |
google.com |
Search Engines, Technology |
www.googletagmanager.com |
Technology |
unpkg.com |
Technology |
intellimize.co |
Technology |
demandbase.com |
Technology |
www.redditstatic.com |
Technology |
Return to DNS Filtering.