Skip to main content

Tutorial: Secure DNS Traffic and Use DNS-Based Content Filtering

Abstract

Learn how to set up CloudConnexa DNS security and DNS-based content filtering with Cyber Shield — verify DNS traffic is routed through the WPC tunnel, configure Domain Filtering categories in a Shield Policy, and confirm malicious domains are blocked.

Overview

Use CloudConnexa to improve DNS security by sending DNS queries through the WPC tunnel and applying DNS-based content filtering with Cyber Shield Domain Filtering.

In this tutorial, you will:

  1. Verify that a connected device sends DNS queries through CloudConnexa.

  2. Configure Domain Filtering in a Shield Policy.

  3. Test that CloudConnexa blocks a domain based on its content category.

You'll use nslookup to verify DNS resolution and malware-test-domain.openvpn.com to confirm that Domain Filtering blocks a malicious domain.

For an introduction to Domain Filtering and other Cyber Shield features, refer to About Cyber Shield.

DNS_filtering.png

Before you begin

You need:

Tip

Domain Filtering applies only to DNS queries resolved through CloudConnexa. If DNS Proxy is off, your Domain Filtering rules remain configured but aren't applied.

Encrypted DNS, such as DNS over HTTPS (DoH), can send queries to a third-party resolver and bypass Domain Filtering. Turn off secure or encrypted DNS on the test device before testing Domain Filtering.

If you need to configure a User first, refer to Add a User.

Step 1: Verify DNS resolution through CloudConnexa

First, connect the test device and verify that DNS queries are resolved through CloudConnexa.

  1. Launch OpenVPN Connect.

  2. Connect to your CloudConnexa WPC.

  3. Open a command prompt or terminal.

  4. Run an nslookup command for a domain. For example:

    nslookup openvpn.net
  5. Review the DNS server address in the response.

    • When DNS resolves through CloudConnexa, the DNS server address is within the 100.96.0.0/11 range. For example:

      Server:  UnKnown
      Address:  100.96.2.65

      Tip

      Server may display UnKnown if the DNS server IP address doesn't resolve to a hostname. This doesn't indicate a DNS resolution problem.

    Note

    The specific DNS server IP can vary. Verify that the address belongs to 100.96.0.0/11 rather than looking for a specific IP address.

If the DNS server isn't in the CloudConnexa range, verify the device's DNS configuration and that DNS Proxy is on before continuing.

For a more detailed DNS-only workflow, refer to Tutorial: Use CloudConnexa to Secure DNS Traffic.

Step 2: Configure DNS-based content filtering

Cyber Shield Domain Filtering lets you monitor or block DNS requests based on content categories.

Domain Filtering is configured per Shield Policy. The policy assigned to a User Group determines which Domain Filtering settings apply to its users.

If you haven't created custom Shield Policies, configure the Default Policy to apply filtering to User Groups that aren't assigned another policy.

  1. Select Shield → Policies.

  2. Select the edit icon for the Shield Policy you want to configure.

  3. Select the Domain Filtering tab.

  4. Turn on Domain Filtering.

  5. Select a protection level or configure individual content categories.

  6. Ensure the Malware category is set to Blocked in your selected protection level or custom category configuration.

  7. If appropriate for your filtering requirements, configure other categories such as Hacking.

  8. Save your changes.

    • The Domain Filtering settings now apply to User Groups covered by that Shield Policy.

For information about assigning different filtering settings to different User Groups, refer to About Shield Policies and Create or Edit a Shield Policy.

For the available protection levels and content categories, refer to Domain Filtering Protection Levels and Content Categories.

Step 3: Verify that Domain Filtering blocks a malicious domain

Use the OpenVPN test domain to verify that the policy blocks a domain categorized as Malware.

  1. Verify that the test device is connected to CloudConnexa.

  2. Verify that the User Group for your test user uses the Shield Policy you configured.

  3. Open a web browser on the test device.

  4. Navigate to: malware-test-domain.openvpn.com.

  5. Verify that access is blocked.

    Tip

    Depending on the browser, you may see an error such as: "This site can't be reached."

The blocked test confirms that the device's DNS query was evaluated by the Shield Policy's Domain Filtering configuration.

If the domain isn't blocked:

  1. Verify that Malware is blocked in the policy's Domain Filtering tab.

  2. Verify that the test user's User Group uses the expected Shield Policy.

  3. Verify that DNS Proxy is on.

  4. Use nslookup again to verify that DNS resolves through the CloudConnexa 100.96.0.0/11 range.

  5. Verify that secure or encrypted DNS, including DoH, isn't enabled on the test device or browser.

What happens next

Your connected users can now send DNS queries through CloudConnexa and receive DNS-based content filtering according to their Shield Policy.

You can create additional Shield Policies when different User Groups require different filtering. You can also:

  • Use the Domain Allow List to allow specific domains that would otherwise be blocked.

  • Use the Domain Block List to block specific domains regardless of their content category.

  • Review Domain Filtering events from Shield → Overview and Shield → Metrics.