In this article
Use Allow and Block Lists to control query traffic by defining lists of domains to allow or deny within the organization. Even Internationalized Domain Names can be added, making these lists a key component of network security. Allow and Block Lists are the section of Filtering Policies that customizes what users can and cannot access.
Review the Filtering Policy hierarchy before creating Allow and Block Lists to make sure the policy configuration meets the desired outcomes.
Allow List and Block List entry format
Add up to 15,000 domains to the Allow List and Block List based on their Fully-Qualified Domain Name (FQDN), using the convention subdomain.example.org. Domains can be allowed or blocked at every level of the hierarchy. The following table describes each level.
| Example | Result |
| subdomain.example.org | Allows or blocks a particular subdomain |
| example.org | Allows or blocks an entire domain name |
| org | Allows or blocks all .org top-level domains (TLDs) |
Failure to follow this format can result in network error messages, or in domains not being allowed or blocked by the policy.
FQDN formatting basics
The following table compares correct and incorrect entry formats.
| Correct format | Incorrect format | Details |
| yahoo.com | www.yahoo.com | DNSFilter automatically also blocks the www subdomain, so add yahoo.com to the list and www.yahoo.com is also included. Prepending www functions as a subdomain-level block, where a domain-level block is usually what is desired. |
| facebook.com | https://facebook.com | URLs are not accepted by DNSFilter. Entries must be FQDNs. |
| example.org | 198.251.90.71 | IP addresses are not recommended because they may change and filtering would be circumvented. |
| ru | *.ru | Block TLDs by their name, such as ru, cn, or tr. |
| ingest.sentry.io | %2a.ingest.sentry.io | Avoid special characters at the beginning or end of the FQDN. |
Caution: Do not add the "." to top-level domain entries. This causes an error.
Note: Domains consisting only of a bare top-level domain, such as ru, top, or xyz, display the Top Level Domains category in the Allow or Block List. This category is visibility-only and does not appear as a selectable option in Filtering Policy category blocking. It does not change how the entry is filtered. Existing TLD entries added before this change may still display as Uncategorized.
Common Allow List and Block List scenarios
The following table describes common formatting scenarios.
| Scenario | What to do |
| Allow or block all subdomains of a website | Add the domain name or TLD to the Allow or Block List. This allows or blocks all subdomains, except for some websites in which a subdomain is classified differently by DNSFilter than the parent domain. |
| Allow or block CNAME records | Add all the CNAMEs in the chain to the Allow or Block List, or allow or block the associated category in the Filtering Policy. |
| Fix an error message | An error message typically means an entry was added in an incorrect format. Resolve a network error by checking the entry format against the FQDN formatting basics. |
Add to Allow or Block Lists
Upload entries to the Allow List or Block List list in three ways:
- Individual entry
- Bulk CSV import
- From the DNS Query Log
Add an individual entry
Add entries one at a time when including a note or completing quick requests to modify access.
To add an individual entry:
- From the DNSFilter dashboard, navigate to Policies and select Filtering.
- Select the policy to edit, or select Add Policy to create a new policy.
- Select the Allow List or Block List tab.
- Select Add to List.
- Enter the FQDN.
-
Optional: Add a note.
Notes have a 512-character limit.
-
Select Add.
Repeat steps 1-7 for each domain.
- Select Save Policy.
- Select Continue to apply the update.
The entry is added to the policy.
List entry notes
The Notes field is useful to add detailed notes about why specific domains were added to a policy, such as an internal ticket request or a tools or software-related domain.
The note is not linked to the domain itself, which means that if a domain is deleted from a list and later re-added, the note will not re-populate. Notes do not display in other areas of the app, such as the DNS Query Log or Policy Audit Log. Notes can be edited after an entry is added by selecting Edit from the row Actions menu.
Import a CSV list
Add list entries in bulk, up to 2,000 entries at a time, with Import.
To import a CSV list:
- Create a list of the domains to allow or block as a simple text file in a program like Google Sheets or Microsoft Excel, entering one domain per line.
- Save the file as .csv.
- From the DNSFilter dashboard, navigate to Policies and select Filtering.
- Select the policy to edit, or select Add Policy to create a new policy.
- Select the Allow List or Block List tab.
- Select Import.
- Select the .csv file.
- Select Open.
- Select Save Policy.
- Select Continue to apply the update.
The list is added to the policy.
Export an Allow or Block List
Export a .csv file of the full Allow List or Block List of any Filtering Policy from the dashboard. Notes and Categories are not included in this download.
To export an Allow List or Block List:
- Navigate to the policy's Allow List or Block List tab.
- Select Export.
The file downloads to the local device.
Comments
0 comments
Please sign in to leave a comment.