0% found this document useful (0 votes)
14 views20 pages

How To Block DNS Queries Using App Control Advanced

This document provides instructions for blocking DNS queries using App Control Advanced signatures on SonicWall firewalls running different versions of SonicOS. The steps include enabling App Control, selecting the DNS protocol from the list of signatures, and blocking individual signatures or the entire DNS application group. Blocked DNS queries will be logged for monitoring.

Uploaded by

sreejishtpk
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views20 pages

How To Block DNS Queries Using App Control Advanced

This document provides instructions for blocking DNS queries using App Control Advanced signatures on SonicWall firewalls running different versions of SonicOS. The steps include enabling App Control, selecting the DNS protocol from the list of signatures, and blocking individual signatures or the entire DNS application group. Blocked DNS queries will be logged for monitoring.

Uploaded by

sreejishtpk
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 20

View Page online: https://www.sonicwall.

com/support/knowledge-base/how-to-block-dns-queries-using-app-control-advanced/170505827678272/

How to block DNS queries using App


Control Advanced
Description
The App Control Advanced signatures for DNS includes country code top-level domains, DNS queries and responses and a
signature to block the new .xxx top level domain. A SonicWall administrator can choose to enable these signatures in any of
the following methods:
Block the whole DNS application group, which will block all DNS queries passing through the SonicWall.
Block individual signatures. For Example, .cn to block China domains; .xxx to block adult entertainment domains.

Resolution for SonicOS 7.X


This release includes significant user interface changes and many new features that are different from the
SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

Login to the SonicWall Management GUI.

Navigate to Policies | Security Services | App Control | Status/Settings page.

Enable the check box under Enable App Control and Accept.

On Signatures tab, select PROTOCOLS under Category.

From the drop down under Application, select DNS Protocol.


Set Viewed by to Signature.

Blocking Individual signatures:

Click on the Configure button on the signature you wish to block. In this example, we have chosen
Standard Query .xxx Adult Entertainment Domains -SID 6821.

In the Edit App control signature window set Enable under Block and Log.
Click OK to save the settings.

Blocking DNS Application group:

Click on the Configure icon under Application with DNS selected.

In the App Control App Settings Window, select Enable under Block and Log.
Click OK to save.

Enabling Application Control on Zones:

Navigate to Objects |Match Objects | Zones.

Click on Configure button on the Zone on where you want to enable Application Control.

Enable Application Control Service.


Click Save to save settings.

Logging DNS queries from behind the SonicWall will be blocked and log messages will be generated under
Monitor | Logs | System Logs

Resolution for SonicOS 6.5


This release includes significant user interface changes and many new features that are different from the
SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Login to the SonicWall Management GUI.

Navigate to the Firewall | App Control Advanced page.

Check the box under Enable App Control and click on the Accept button at the top to enable App Control.

Under Manage | Rules | App Control select PROTOCOLS under Category; select DNS Protocol under

Application; select Signature under Viewed By, to list the signatures available under this application:

Blocking individual signatures

Click on the configure icon of a signature you wish to block. In this example, we have chosen Standard Query .xxx

Adult Entertainment Domains - SID 6821.

In the Edit App Control Signature window, select Enable under Block and Log.

Click on OK to save.
Blocking DNS application group
Click on the configure icon under Application with DNS selected.

In the Edit App Control App window, select Enable under Block and Log.

Click on OK to save.
Enabling Application Control on zones

Navigate to Manage | Network | Zones

Click on the configure button under the zone where you want enable App Control.

Check Enable App Control Service.

Click on OK to save.
Logging DNS queries from behind the SonicWall will be blocked and log messages similar to the following will be
generated under Investigate | Event Logs
Resolution for SonicOS 6.2 and Below
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are
generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.

Login to the SonicWall Management GUI.

Navigate to the Firewall | App Control Advanced page. NOTE: In Gen5 Tz devices this page is under Security

Services | App Control

Check the box under Enable App Control and click on the Accept button at the top to enable App Control.

Under App Control Advanced | View Style select PROTOCOLS under Category; select DNS under Application;

select Signature under Viewed By, to list the signatures available under this application:
Blocking DNS application group
Click on the configure icon under Application with DNS selected.

In the Edit App Control App window, select Enable under Block and Log.

Click on OK to save.

Blocking individual signatures

Click on the configure icon of a signature you wish to block. In this example, we have chosen Standard Query .xxx

Adult Entertainment Domains - SID 6821.


In the Edit App Control Signature window, select Enable under Block and Log.

Click on OK to save.
Blocking a country code top-level domain
Click on the configure icon of a signature you wish to block. In this example, we have chosen Standard Query .cn

China Domains - SID 6822.

In the Edit App Control Signature window, select Enable under Block and Log.

Click on OK to save.
Enabling Application Control on zones
Navigate to Network | Zones

Click on the configure button under the zone where you want enable App Control.

Check Enable App Control Service.

Click on OK to save.
LoggingDNS queries from behind the SonicWall will be blocked and log messages similar to the following will be
generated under Log | View:

You might also like