Skip to main content
Print

Domain Filtering

Overview

Domain Filtering allows an administrator to create lists of domains that are
always allowed or always blocked by the zWAN Edge Controller.

The Allowed List can be used when a trusted domain must remain accessible.
The Blocked List can be used to prevent access to an unwanted domain when the
Domain Blocklist feature is supported on the device.

Prerequisites

Before configuring Domain Filtering:

  1. Log in to the local zWAN Edge Controller web interface with an account that
    can manage security settings.
  2. Confirm that DNS is configured and enabled on the Edge Controller.
  3. Identify whether the domain must be added to the Allowed List or the
    Blocked List.

If DNS is not enabled, the Edge Controller displays a warning and provides a
link to configure DNS in the Classic UI.

Domain Filtering page showing the Allowed List and Blocked List

Domain Filtering in the current Local Web UI.

Functionality

Domain Filtering provides the following lists:

  • Allowed List: Domains in this list are always allowed.
  • Blocked List: Domains in this list are always blocked when the Domain
    Blocklist feature is supported.

Each entry contains:

  • Domain: The domain to allow or block. This field is required.
  • Description: Optional information that identifies the purpose of the
    entry.

A domain cannot be added to the Allowed List if it already exists in the Blocked
List. In the same way, a domain cannot be added to the Blocked List if it already
exists in the Allowed List.

Add a Domain to the Allowed List

  1. From the main menu, select Security.
  2. Select Domain Filtering.
  3. Select Allowed List.
  4. Click Add Allowed Domain.
  5. In Domain, enter the domain that must always be allowed.
  6. In Description, optionally enter information about the entry.
  7. Review the domain and click the confirmation control to add it.
  8. Confirm that the new domain appears in the Allowed List.

Add Allowed form with Domain and Description fields

Add a domain to the Allowed List.

Note: If the domain already exists in the Blocked List, remove it from that
list before adding it to the Allowed List.

Add a Domain to the Blocked List

  1. From the main menu, select Security.
  2. Select Domain Filtering.
  3. Select Blocked List.
  4. Click Add Blocked Domain.
  5. In Domain, enter the domain that must always be blocked.
  6. In Description, optionally enter information about the entry.
  7. Review the domain and click the confirmation control to add it.
  8. Confirm that the new domain appears in the Blocked List.

Add Blocked form with Domain and Description fields

Add a domain to the Blocked List.

Note: If the domain already exists in the Allowed List, remove it from that
list before adding it to the Blocked List.

Remove a Domain

  1. From the main menu, select Security.
  2. Select Domain Filtering.
  3. Open the Allowed List or Blocked List containing the domain.
  4. Locate the domain entry.
  5. Select the delete control for the entry.
  6. Confirm the removal when prompted.
  7. Confirm that the domain no longer appears in the list.

Removing an entry returns the domain to the behavior defined by the remaining
security configuration.

Verify the Configuration

After adding or removing a domain:

  1. Confirm that the entry appears in the intended list.
  2. Confirm that the same domain does not appear in the opposite list.
  3. Allow up to 30 seconds for the displayed list to refresh.
  4. Test access from an authorized client according to your organization’s change
    and validation procedure.

If the result is not as expected, review the other DNS, firewall, and filtering
settings that may apply to the traffic.

Troubleshooting

DNS is not enabled

Domain Filtering requires DNS to be configured on the Edge Controller.

  1. Follow the warning displayed on the Domain Filtering page.
  2. Select the provided action to open DNS configuration in the Classic UI.
  3. Configure and enable DNS according to the DNS Server procedure.
  4. Return to Security → Domain Filtering and add the domain again.

DNS-disabled warning with the Classic UI configuration action

Configure DNS before adding a Domain Filtering entry.

The domain is not accepted

  • Confirm that the Domain field is not empty.
  • Verify that the domain was entered correctly.
  • If the interface reports that the value is invalid, use a domain format
    supported by the installed release.

The domain exists in the opposite list

An allowed domain cannot also be present in the Blocked List, and a blocked
domain cannot also be present in the Allowed List.

  1. Open the opposite list.
  2. Locate and remove the existing entry.
  3. Return to the intended list.
  4. Add the domain again.

The saved entry does not appear immediately

The Domain Filtering lists refresh periodically. Wait up to 30 seconds and check
the list again.

Notes

  • The Description field is optional but is recommended to explain why an
    entry was created.
  • Confirm support for the Domain Blocklist feature before relying on the Blocked
    List.
  • Test security changes from an authorized client before considering the change
    complete.
  • Wildcard and subdomain matching can vary by product version. Use only formats
    validated for the installed release.
  • To roll back a change, remove the entry from the list in which it was added.
Table of Contents