icon-zia.svg
Secure Internet and SaaS Access (ZIA)

About DNS Application Groups

Watch a video about DNS Application Groups

Through DNS Application Groups, you can create groups based on DNS tunneling traffic as well as other web applications. By allowing or blocking traffic at the DNS level, you gain greater granular control and can create new Firewall policies applied specifically to these groups. To learn more, see Detecting and Controlling DNS Tunnels.

DNS application groups provide the following benefits and enable you to:

  • Group legitimate DNS tunnels, commonly blocked DNS tunnels, unrecognized DNS tunnels, and DNS network applications (not to be confused with DPI-based network applications) to manage them collectively in the DNS Control policy.
  • Enforce condition-based actions on DNS traffic using the DNS Control policy to protect your network traffic against DNS tunneling.
  • Investigate and analyze the DNS tunnels detected in your network using Zscaler DNS logs.

About the DNS Application Group Page

On the DNS Application Group page (Administration > Network Applications), you can do the following:

  1. Add a DNS application group.
  2. View a list of all DNS Application Groups. For each group, you can view the following:
    • Name: The of your DNS application group. You can sort this column.
    • Applications: The DNS tunnel categories, and web applications included in your group.
    • Description: The description of the group, if available. You can sort this column.
  3. Edit a DNS application group.
  4. Modify the table and its columns.
  5. Search for a DNS application group.
  6. Go to the Network Applications page.
  7. Go to the Network Application Groups page.

Numbered diagram of the options available in the add DNS application groups page

Related Articles
About Network ServicesConfiguring Network ServicesModifying Predefined Network ServicesAbout Network Service GroupsConfiguring Network Service GroupsAbout Network ApplicationsAbout Network Application GroupsConfiguring Network Application GroupsAbout Application Service GroupsAbout Source IP GroupsConfiguring Source IP GroupsAbout Destination IP GroupsConfiguring Destination IP GroupsAbout DNS Application GroupsConfiguring DNS Application GroupsAbout IP PoolAbout Threat CategoriesAdding Threat CategoriesAbout EDNS Client Subnet (ECS) Injection Adding EDNS Client Subnet (ECS) PrefixesAbout DNS GatewaysAdding DNS Gateways