How Direct-to-IP Detection Works
Your enforcement point passively inspects DNS traffic crossing each zone and maintains
a local DNS Seen Table of IP address and TTL pairs for each resolved domain. It also
forwards a copy of this DNS response data to Advanced IP Defense. Advanced IP Defense then builds a DNS Seen Table unique to your tenant that
tracks every IP address resolved through DNS and when that resolution expires,
enabling cross-firewall detection in asymmetric routing environments.
When your enforcement point queries Advanced IP Defense about an IP address, Advanced IP Defense checks
whether that IP appears in your tenant's DNS Seen Table with a valid (non-expired)
entry. If the IP has no DNS history or the entry has expired beyond a grace period,
Advanced IP Defense returns a direct-to-IP verdict. The grace period (currently 300 seconds)
accounts for transmission delays and clients that use slightly expired cache
entries.
Direct-to-IP detection applies only to publicly routable IP addresses in outbound traffic.
Advanced IP Defense allowlists all private IP ranges, so protocols that operate exclusively on
internal networks (such as DHCP, mDNS, and NetBIOS) do not trigger false positives.
Do not apply direct-to-IP rules to inbound traffic — direct-to-IP detection is designed
for outbound sessions where a client initiates a connection without resolving the
destination through DNS.