Chapter 17 Reputation Filter
USG FLEX H Series User’s Guide
281
17.3.1 DNS Threat Filter Allow List Screen
Use this screen to create allow list entries. The Zyxel Device will not reply with a DNS reply packet
containing a default or custom-defined IP address when a DNS query packet contains an FQDN in the
allow list.
Click Security Service > Reputation Filter > DNS Threat Filter > Allow List to display the configuration
screen as shown next.
Figure 176 Security Service > Reputation Filter > DNS Threat Filter > Allow List
The following table describes the labels in this screen.
Domain name to
test
Enter an FQDN and click the Query button to check if the domain name is associated with
suspicious activities that could pose a security threat to users or their computers.
Apply Click Apply to save your changes.
Reset Click Reset to return the screen to its last-saved settings.
Table 140 Security Service > Reputation Filter > DNS Threat Filter
LABEL DESCRIPTION
Table 141 Security Service > Reputation Filter > DNS Threat Filter > Allow List
LABEL DESCRIPTION
Enable Select this check box and the Zyxel Device will not reply with a DNS reply packet
containing a default or custom-defined IP address when a DNS query packet contains an
FQDN in the white list.
Add Click this to create a new entry. To add an FQDN, type a Fully-Qualified Domain Name
(FQDN) of a web site. An FQDN starts with a host name and continues all the way up to
the top-level domain name. For example, www.zyxel.com.tw is a fully qualified domain
name, where “www” is the host, “zyxel” is the third-level domain, “com” is the second-
level domain, and “tw” is the top level domain. Underscores are not allowed. Use "*." as a
prefix in the FQDN for a wildcard domain name (for example, *.example.com).
Edit Select an entry and click this to be able to modify it.
Remove Select an entry and click this to delete it.
Active To turn on an entry, select it and click Active.