Policy management
You can manage DNS traffic filtering policies on the Policies tab of the BI.ZONE Secure DNS web interface.
To view statistics for these policies, on the Statistics tab of the web interface, locate the Policies widget and click the policy you are interested in. For more information on detailed statistics pages for each policy, see the Policies widget.
Policies are grouped by the stage at which they are applied: DNS query and DNS response.
At the DNS query stage, BI.ZONE Secure DNS uses the following traffic filtering policies:
Anti DDoS Servfail. Protects against DDoS attacks that flood the infrastructure with DNS queries, increasing the load. The policy optimizes DNS query processing by redirecting or replacing DNS responses containing the SERVFAIL error code with responses that return the NOERROR code. If you need to monitor such DNS responses yourself, do not enable this policy.
Domain lists. Allows you to create whitelists, blacklists, monitoring lists, and redirect lists for FQDNs, including by using regular expressions (regex). Each DNS query is first matched against the FQDN lists and then, if no match is found, against the regular expression lists.
RKN register for domains. Uses the Unified Register of Prohibited Information maintained by Roskomnadzor to track DNS queries to domains from this register and block or redirect such queries to isolated IP addresses.
TI for FQDN. Uses indicators of compromise (IoCs) from the TI database to monitor DNS queries to malicious domains and either block or redirect them to isolated IP addresses.
Web Category. Allows you to configure the DNS query processing based on the FQDN’s web category. You can select prohibited web categories and configure actions for DNS queries to FQDNs that do not belong to any of the web categories. If a query is blocked, further processing is terminated and a response with the NXDOMAIN error code is returned.
Anti DNS Tunnel. Allows you to detect DNS tunnels and either block or redirect DNS queries to malicious domains, sending them to isolated IP addresses. Second- and third-level domains involved in DNS tunneling are automatically added to the policy's blacklist. You can add trusted domains to the policy's whitelist. As a general rule, add second-level domains to the whitelist. However, if a second-level domain is on the list of top-level domains (TLD), add the third-level domain instead.
Anti DGA. Uses DGA probability thresholds to monitor DNS queries to algorithmically generated domains (DGA) and either block or redirect such queries to isolated IP addresses.
At the DNS response stage, BI.ZONE Secure DNS uses the following traffic filtering policies:
DNSSEC. Verifies the authenticity of DNS responses by using digital signatures and the DNSSEC chain of trust. The policy is always enabled, but you can set exceptions for specific domains.
Anti DNS Rebinding. Protects against DNS Rebinding attacks. The policy removes private IP addresses and networks from resource records if they were obtained from public DNS servers. When the policy is enabled, the networks specified in RFC 1918 are automatically added to the list of private IP addresses.
RKN register for IP. Removes IP addresses found in the Unified Register of Prohibited Information maintained by Roskomnadzor from resource records. When receiving DNS responses, IP addresses and networks are checked against the Roskomnadzor register.
BlackList for IP. Allows you to remove IP addresses found on the IP blacklist from resource records. When receiving DNS responses from authoritative DNS servers, the policy matches IP addresses (IPv4 and IPv6) against the IP blacklist. You can configure actions to take when an IP address is found on the blacklist.
TI for IP. Allows you to remove IP addresses found in the TI database from resource records. When receiving DNS responses from authoritative DNS servers, the policy matches IP addresses (IPv4 and IPv6) against the TI database. You can configure the action to take when an IP address exceeds the IoC confidence threshold.
Policies can have one of the following statuses:
Enabled
Disabled
Policies can perform the following actions on DNS traffic:
Allow
Block
Redirect