| Where Can I Use
This? | What Do I Need? |
|
|
Advanced DNS Resolver License
|
You can specify a list of custom FQDNs or EDLs (External Dynamic Lists) that the
Advanced DNS Security Resolver can reference to apply a user-specified action, such
as allow, block, alert, or sinkhole when the DNS query is made to a qualifying
domain. The Advanced DNS Security Resolver provides several mechanisms for
evaluating domains based on several criteria, this includes:
Custom FQDN Lists (Override)
EDL Definitions (Override)
DNS Categories from content-updates, as well as
domain categories that are derived using a combination of cloud-based
analysis and machine learning powered by its Precision AI engine, which
inspects DNS traffic for malicious patterns
Because these domain/category lists can be independently configured with unique
actions for a given entry, the concluding action to be taken is based on the order
of precedence, which is shown above. That means, for example, duplicate domains
contained in both the custom FQDN list and EDL will use the action contained in the
FQDN list (not the EDL), while any matching internal domain types (either
user-specified or built-it) will, in turn, have precedence over both. The DNS
categories are placed lowest in the order of precedence due to their broad
applicability in comparison to the specificity afforded by the other domain
lists.