SonicOS 7.1 Rules and Policies for Classic Mode

Creating DNS Policy Rules

You need to define DNS Policy Rules in order to enable DNS Filtering.

To create a DNS Policy Rules

  1. Navigate to POLICY | Rules and Policies > DNS
  2. Click Add Top at the bottom left of the screen. The Adding DNS Policy dialog displays.

  3. In the Name field, enter a name for the policy.
  4. In the Tags field, enter any tags you want associated with the policy. (This field is optional.)
  5. In the Description field, enter a brief description of the policy. (This field is optional.)
  6. For the Action, select Filter. SonicOS proxies connections matching this rule using the 4 to 4 mode and completes any action specified in the profile. Actions are Allow/Block/Negative/Forged IP.
  7. From the Schedule list, select when you want the policy to be active.
  8. Select Enable to enable the policy.
  9. From the Profile list, select the DNS profile you want associated with the policy.
  10. On the Source/Service tab:
    1. From the Zone/Interface list, select the zone affected by the policy.
    2. From the Address list, select an IP address for the policy.
    3. From the Service list, select the service to be used by the policy.
  11. On the Optional Settings tab:
    1. In the Number of Connections allowed (% of max connections) field, enter the maximum number of connection (as a percentage of the number of allowed connections).

    2. Select Enable Connection Threshold for each Source IP to set the maximum number of connections for each source IP address. Enter the number of connections allowed in the field to the right.

  12. Select Show Diagram to display the diagram that shows where the policy operates between the source and the service.
  13. Click Add.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden