Skip to main content
Kraven2323
Staff
Staff
April 26, 2022

Technical Tip: Domain Name threat feed only applicable in DNS filter profile

  • April 26, 2022
  • 0 replies
  • 10056 views
Description

This article describes that from V6.2 onwards the external block list (threat Feed) in firewall policy can be done.

Among one of the categories, Domain name threat feed can be configured.

Solution

It is possible to configure the Domain Name threat feed using the following navigation:

Security Fabric -> External Connectors, select 'Create New' -> Threat Feeds -> Domain Name.

 

Kraven2323_0-1650960677588.png

 

The Domain Name contains one domain per line. Simple wildcards are supported.

It is available as a Remote Category in DNS Filter profiles.

 

Example:

 

mail.*.example.com
*-special.example.com
www.*example.com
example.com

 

Kraven2323_1-1650960753017.png

 

The Domain Name threat feed can only be applied to the DNS filter profile.

 

Kraven2323_2-1650961655446.png

 

Note :

  • If using local DNS, apply the DNS filter on that local DNS server firewall policy.
  •  For Testing and verifying if the thread feed working or not in the system give primary DNS 8.8.8.8 secondary DNS: blank, so DNS traffic will not go to local DNS.

 

Related document:

External resources for DNS filter

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!