Policy
A policy is a named set of rules — what to block, whether to enforce or only watch, and when. You can have several (for example Staff, Guest Wi-Fi, Servers) and assign them to users, groups, devices or endpoints.
Create a policy
- Go to Secure Access → DNS Filtering → Policy.
- Type a name in the box, e.g.
Guest Wi-Fi, and click New policy. - Select it from the pills at the top to edit it.
Rename and Delete sit next to the name. You cannot delete the only policy, and you cannot delete one that endpoints still use — the error tells you how many.
Always finish with Save policy. Nothing takes effect until you do.
Switches
| Setting | What it does |
|---|---|
| Filtering enabled | Master switch for this policy |
| Mode | Block returns NXDOMAIN · Monitor only logs |
| Block malicious domains | Malware, botnet command-and-control and phishing, from threat intelligence feeds — keep on. Insights still records which of those a block was, so you can tell a C2 beacon from someone clicking a fake login page |
| Block page | Show a branded page instead of a generic browser error. Design it in Block Page |
| SafeSearch | Forces SafeSearch on Google, Bing and DuckDuckGo at the DNS layer — nothing to configure on the device |
| YouTube Restricted Mode | Off, Moderate or Strict |
| Time schedule | Enforce only during set hours — see below |
Set Mode to Monitor for the first few days. You get a "Would block" tile on the Overview showing exactly what enforcement would have stopped, without a single support ticket. Switch to Block once the list looks right.
Categories
Categories are grouped: Security, Filter bypass, Content, Productivity, AI / GenAI, Other. Click a category chip to toggle it (● on, ○ off); click the domain count next to it to browse the actual domains, with a prefix filter and paging.
Do not skip Filter bypass. The hint next to that group says it: "Block these or users can route around every rule above." It covers public DoH resolvers, proxies and VPN services — leave them open and the rest of your policy is advisory.
If the category list is empty you see "No category feeds have synced yet" — the lists are still downloading. Check the feeds table on the Overview.
Time schedule
Tick Time schedule to reveal the window:
- Pick the days — Sun through Sat. No days selected means every day.
- Set From and to (24-hour times).
- Choose the TZ —
UTCby default, plus the common US, European, Asian and Australian zones.
Outside the window, categories and custom rules relax — but malicious domains always block. The window has to sit inside a single day; overnight ranges are not supported yet.
A typical use: block social media and streaming during business hours, leave the guest network open in the evening, keep threat protection on permanently.