Better transparency for Security Filters (DNS / URL filtering)

Options
tekkie
tekkie Posts: 11 image  Freshman Member
First Comment Friend Collector

Hi everyone,

The security features are generally very good, but sometimes it’s not clear why exactly a website gets blocked.

In my case, the issue was first caused by the DNS filter, and later by the URL filter. It would be really helpful to have a way to test a domain directly in the interface and immediately see which filter or category is blocking it.

This would make troubleshooting and fine-tuning the security settings much faster and clearer for admins.

Best,
Valentin

1 votes

Active · Last Updated

Comments

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,096 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @tekkie

    DNS/URL threat filter provides a test tool to check the category this domain belongs to. Please reference to the screenshots below.

    image.png image.png
    Zyxel Melen


  • tekkie
    tekkie Posts: 11 image  Freshman Member
    First Comment Friend Collector

    Hi @ZyXEL _Melen,

    Yes, that makes sense and technically it works as expected. But in practice, the situation is often a bit different, a customer tells me that a website doesn’t work, so I ask for the domain and what message they saw. Then I see that the DNS filter blocked it, so I whitelist it there, but later it turns out that the URL filter blocks it as well.

    It would be really helpful to have one single interface where you can enter a domain or URL and have it checked across all filters, DNS, URL, SSL inspection, maybe even IP reputation. That would make troubleshooting much faster and more transparent.

    Best,
    Valentin