In this article
DNSFilter offers three deployment options to mix and match to meet filtering and reporting needs: Network Forwarding, Roaming Client, and Relay. This article describes each option, its advantages and considerations, and best use cases.
To set up DNSFilter on a network, see the get started guide.
To migrate from another filtering service, see the onboarding materials for migrating to DNSFilter.
Network Forwarding
Network Forwarding is the easiest way to set up a network to use DNSFilter. It provides a blanket policy that covers all devices on the network, including printers, file servers, and any other node.
Network Forwarding involves changing the network forward settings for DNS to point to one of the DNSFilter anycast IPs, 103.247.36.36 and 103.247.37.37. This can be done at the firewall, router, or modem level, whichever handles outbound traffic.
This causes a portion or all of the network devices to be filtered by DNSFilter. For example, when multiple firewalls or routers are in use but only some are configured to point to DNSFilter, only that part of the network is affected.
This deployment option is useful where there is no control over the user's endpoint and software cannot be installed, such as guest Wi-Fi. Filtering policies still apply even without control of the device.
Where DNSFilter reporting is limited to the WAN level, many firewalls have reporting capabilities that offer device-specific data. This additional resource helps monitor networks and pinpoint user traffic when troubleshooting filtering policies. See the manufacturer's documentation for capability details.
Network Forwarding advantages
- Simple deployment, no software required
- Provides complete coverage of Local Area Network (LAN) devices
Network Forwarding considerations
- Limited to one Filtering Policy, or seven with NAT IPs, per network
- Reporting is limited to the wide-area network (WAN) level
Roaming Client
Roaming Clients monitor and process DNS requests on the device, applying DNSFilter policies locally before forwarding allowed traffic to the appropriate DNS resolver.
Administrators can assign specific policies to a device, user, or group of users that follow them everywhere, on any device. Policies for large groups of computers can be changed using tags. Tag use cases include teachers and students, corporate departments, and public and private computers.
Roaming Clients can be deployed using Remote Software Management and Monitoring tools (RMMs) such as Microsoft Intune (Microsoft Endpoint Manager), or installed per device.
Roaming Clients offer per-user and per-device data, like an Active Directory (Entra ID; Azure AD) domain controller. To compare, Network Forwarding offers aggregate data—the whole network—and Relays tie data to specific IP addresses.
DNSFilter integrates with Active Directory using a hybrid deployment setup.
Roaming Client advantages
- Available for all major platforms: Windows, Mac, iOS, Android, Chromebook
- Provides per-device and per-user reporting
- Offsite protection for roaming users
Roaming Client considerations
- Requires software installation
Relay
A Relay is local DNS relay software that applies Filtering Policies by IP or subnet on the network.
A Relay is middleware that manages traffic within the system and determines whether to send DNS queries outbound to the public internet, where DNSFilter filters them, or to a local DNS resolver.
Because the Relay acts as an intermediary, it evaluates each DNS query and determines whether the request is a local query, such as printer.lan, or an external request, such as website.com, then routes it accordingly.
As of January 16, 2025, the DNSFilter Relay performs queries on a persistent TLS connection.
Relay advantages
- Filters by IP or subnet
- Provides per-machine reporting
Relay considerations
- Requires a machine (physical or virtual) or Docker to run with high availability
- Does not provide user-level filtering or user-level reporting like the Roaming Client
Query Log data capture
The following table shows the query data captured for each deployment type (when Limit PII privacy mode is set to Standard).
| Log type | Network Deployment | Roaming Client | DNS Relay |
| FQDN | Yes | Yes | Yes |
| Result | Yes | Yes | Yes |
| Category | Yes | Yes | Yes |
| Policy | Yes | Yes | Yes |
| Application | Yes | Yes | Yes |
| Site | Yes | Yes | Yes |
| Hostname | No | Yes | No |
| Username | No | Yes | No |
| LAN IP | No | Yes | Yes |
| WAN IP | Yes | Yes | Yes |
Comments
0 comments
Please sign in to leave a comment.