Skip to main content

Policy

A policy is a named set of rules — what to block, whether to enforce or only watch, and when. You can have several (for example Staff, Guest Wi-Fi, Servers) and assign them to users, groups, devices or endpoints.

Create a policy

  1. Go to Secure Access → DNS Filtering → Policy.
  2. Type a name in the box, e.g. Guest Wi-Fi, and click New policy.
  3. Select it from the pills at the top to edit it.

Rename and Delete sit next to the name. You cannot delete the only policy, and you cannot delete one that endpoints still use — the error tells you how many.

Always finish with Save policy. Nothing takes effect until you do.

Switches

SettingWhat it does
Filtering enabledMaster switch for this policy
ModeBlock returns NXDOMAIN · Monitor only logs
Block malicious domainsMalware, botnet command-and-control and phishing, from threat intelligence feeds — keep on. Insights still records which of those a block was, so you can tell a C2 beacon from someone clicking a fake login page
Block pageShow a branded page instead of a generic browser error. Design it in Block Page
SafeSearchForces SafeSearch on Google, Bing and DuckDuckGo at the DNS layer — nothing to configure on the device
YouTube Restricted ModeOff, Moderate or Strict
Time scheduleEnforce only during set hours — see below
Start in Monitor

Set Mode to Monitor for the first few days. You get a "Would block" tile on the Overview showing exactly what enforcement would have stopped, without a single support ticket. Switch to Block once the list looks right.

Categories

Categories are grouped: Security, Filter bypass, Content, Productivity, AI / GenAI, Other. Click a category chip to toggle it ( on, off); click the domain count next to it to browse the actual domains, with a prefix filter and paging.

Do not skip Filter bypass. The hint next to that group says it: "Block these or users can route around every rule above." It covers public DoH resolvers, proxies and VPN services — leave them open and the rest of your policy is advisory.

If the category list is empty you see "No category feeds have synced yet" — the lists are still downloading. Check the feeds table on the Overview.

Time schedule

Tick Time schedule to reveal the window:

  1. Pick the days — Sun through Sat. No days selected means every day.
  2. Set From and to (24-hour times).
  3. Choose the TZUTC by default, plus the common US, European, Asian and Australian zones.

Outside the window, categories and custom rules relax — but malicious domains always block. The window has to sit inside a single day; overnight ranges are not supported yet.

A typical use: block social media and streaming during business hours, leave the guest network open in the evening, keep threat protection on permanently.