Skip to main content

Configure Domain Filtering for a Shield Policy

Abstract

You can configure the content categories to block using preset Protection Levels or by choosing the Custom Protection Level and selecting individual content categories to block.

You can configure the content categories to block using preset protection levels or by choosing the Custom Protection Level and selecting individual content categories to block. To learn more about the content categories, content category groups, and protection levels, refer to Domain Filtering

To choose the content categories to block, follow the steps below:

  1. Navigate to Shield > Configuration.

  2. Click Categories in the section navigation that appears to the right under Domain Filtering.

  3. Select one of the four Protection Levels that block content categories: Basic Protection, Safe Browsing, High Productivity, or Custom.

    1. The resulting content categories that will be blocked appear in the Selected Categories section.

    2. When the Custom Protection Level is selected, you can search for and select specific content categories to block from the list in the Selected Categories section.

  4. Click Update.

Overview

Configure Domain Filtering per Shield Policy to monitor or block domains based on content category. On the policy's Domain Filtering tab, turn on Domain Filtering and select a protection level that determines which content categories CloudConnexa monitors or blocks.

Choose from five protection levels using the horizontal selector: Monitor Only, Basic Protection, Safe Browsing, High Productivity, or Custom. The preset protection levels provide predefined category settings, while Custom lets you configure individual categories.

For more information about how Shield Policies apply filtering settings, refer to About Shield Policies.

For details about the available protection levels and content categories, refer to Domain Filtering.

Before you begin

Ensure you have a Shield Policy to configure.

You can configure the Default Policy or a custom Shield Policy. To create a custom policy, refer to Create or Edit a Shield Policy.

Configure Domain Filtering

  1. Navigate to Shield → Policies.

  2. Select the Edit policy icon for the Shield Policy you want to configure or select New Policy.

  3. Select Domain Filtering.

  4. Turn on Domain Filtering.

  5. Use the horizontal selector to select one of the five protection levels:

    Protection Level

    Behavior

    Monitor Only

    Monitors DNS queries without blocking any content categories.

    Basic Protection

    Monitors DNS queries and blocks the Malicious category group.

    Safe Browsing

    Monitors DNS queries and blocks the Malicious, Adult Content, Aggressive Content, Alcohol, Tobacco, Illegal Drugs, and Hacking and Cracking category groups.

    High Productivity

    Monitors DNS queries and blocks all eight category groups.

    Custom

    Lets you choose whether to monitor or block each of the 43 content categories.

  6. If you select Custom, configure the content categories you want to monitor or block:

    1. Browse the content category groups or search by name to find a specific category.

    2. Set individual categories to Monitored or Blocked.

    3. Use Monitor All or Block All to change all categories within a content category group.

    4. Review Selected Categories to verify your selections.

      Note

      If no content categories are blocked, the protection level falls back to Monitor Only.

  7. Save your changes.

    • The selected Domain Filtering settings apply to users and resources protected by that Shield Policy.

Change between Custom and preset protection levels

Change the protection level when you want to use different Domain Filtering settings for the Shield Policy.

  1. Open the Shield Policy and select the Domain Filtering tab.

  2. Select a different protection level from the horizontal selector:

    • To customize a preset, change from Basic Protection, Safe Browsing, or High Productivity to Custom.

      CloudConnexa keeps the current category selections so you can modify individual content categories.

    • To replace a Custom configuration with a preset, select Basic Protection, Safe Browsing, or High Productivity.

      CloudConnexa resets your custom category selections and applies the categories defined by the selected preset.

    • To monitor categories without blocking them, set all content categories to Monitored.

      If no content categories are blocked, CloudConnexa automatically changes the protection level from Custom to Monitor Only.

  3. Review the monitored and blocked category counts to verify the new configuration.

  4. Save your changes.

    Important

    Changing from Custom to Basic Protection, Safe Browsing, or High Productivity replaces your custom category selections with the selected preset.

What happens next

CloudConnexa applies the selected Domain Filtering protection level to DNS activity covered by the Shield Policy.

You can further customize Domain Filtering for the policy by:

  • Adding domains to the Domain Allow List to keep specific domains reachable even when their content category is blocked.

  • Adding domains to the Domain Block List to always block specific domains.

Refer to Domain Allow List and Domain Block List.

Tip

Changes may not apply immediately to domains that were previously visited because of local caching.