Skip to main content

Custom allow / deny

Your own list, on top of the categories and threat feeds. Rules belong to one policy — the header tells you which one ("Rules for: Guest Wi-Fi"); switch policy on the Policy tab.

Add one rule

  1. Go to Secure Access → DNS Filtering → Custom rules.
  2. Type the domain.
    • example.com matches the domain and all its subdomains.
    • *.example.com matches only the subdomains, not the bare domain.
  3. Choose Block or Allow.
  4. Click Add.

Each rule appears in the list below with an ALLOW or BLOCK badge and a Remove link.

Import a list

Click + Bulk import (paste a list):

  1. Paste your domains into the textarea — one per line, or comma-separated.
  2. The action is whatever is set in the Block / Allow select above the box — the helper text reminds you which one is active.
  3. Click Add all.

You get a summary like "Added 184, skipped 12 duplicate(s)". Up to 2,000 domains per import; duplicates are skipped silently.

Which rule wins

An Allow rule beats a category block — that is how you unblock a single business tool inside a category you otherwise want closed. It does not override malware and phishing feeds: if a domain is a known threat, it stays blocked.

Worth doing

  • Allow the SaaS tools your team actually uses before you switch a broad category on.
  • Block the specific domains that show up repeatedly in Most blocked with reason Category if you want them stopped even outside the schedule window.
  • Keep an allow rule list per policy — guests rarely need the same exceptions as staff.
note

Use Check a domain on the Overview tab to see exactly which of your rules matched before you add another one. Two overlapping rules are the most common reason a "block" appears not to work.