icon-zia.svg
Secure Internet and SaaS Access (ZIA)

Configuring DNS Application Groups

Watch a video about DNS Application Groups

To group together the types of DNS tunnels and other web applications that you want to control in a DNS Control rule, create a DNS Application Group. To learn more, see About DNS Application Groups.

To create a group:

  1. Go to Administration > Network Applications.

  1. Go to the DNS Applications Groups tab.
  2. In the DNS Application Groups tab, click Add DNS Application Group.

  1. Enter a Name for the application group. It can have a maximum of 255 characters and can include any standard characters including spaces.
  2. Add DNS Tunnels & Network Apps to the rule. Click the down arrow by and select any number of tunnels and applications that you want to include in the group. You might create a group to include DNS tunnel methods and web applications. that should be allowed for some users, while another could include tunnel methods that are blocked for all users. Click the category name to include all the tunnels or applications in a category. When you are finished, click Done.

  1. (Optional) Enter a Description to add any additional notes or information. The description cannot exceed 10,240 characters.
  2. Click Save and activate the change. After saving and activation, the DNS Application Groups are available for use when creating DNS Filtering rules. They will enable you to Allow or Block the types of traffic that you have identified in your group.
Related Articles
About Network ServicesConfiguring Network ServicesModifying Predefined Network ServicesAbout Network Service GroupsConfiguring Network Service GroupsAbout Network ApplicationsAbout Network Application GroupsConfiguring Network Application GroupsAbout Application Service GroupsAbout Source IP GroupsConfiguring Source IP GroupsAbout Destination IP GroupsConfiguring Destination IP GroupsAbout DNS Application GroupsConfiguring DNS Application GroupsAbout IP PoolAbout Threat CategoriesAdding Threat CategoriesAbout EDNS Client Subnet (ECS) Injection Adding EDNS Client Subnet (ECS) PrefixesAbout DNS GatewaysAdding DNS Gateways