Configuring FQDN Filtering on Zyxel ATP 700 with a Static External IP and Subdomains
In this article, we will discuss how to configure FQDN filtering on the Zyxel ATP 700, which has a static external IP address and subdomains. We will cover the key concepts of FQDN filtering and provide detailed instructions on how to set it up on the Zyxel ATP 700. The article will be divided into several subtitles, each covering a specific aspect of the configuration process.
What is FQDN Filtering?
FQDN (Fully Qualified Domain Name) filtering is a security feature that allows you to block or allow traffic based on the domain name rather than the IP address. This is particularly useful when dealing with dynamic IP addresses or when you want to block traffic from a specific website or domain. FQDN filtering can be configured on most modern firewalls, including the Zyxel ATP 700.
Benefits of FQDN Filtering
FQDN filtering offers several benefits over traditional IP-based filtering. Firstly, it is more flexible as domain names are less likely to change than IP addresses. Secondly, it is easier to manage as you can block or allow traffic based on the domain name rather than having to keep track of IP addresses. Finally, FQDN filtering can provide better security as it allows you to block traffic from known malicious websites or domains.
Configuring FQDN Filtering on Zyxel ATP 700
To configure FQDN filtering on the Zyxel ATP 700, follow these steps:
Log in to the Zyxel ATP 700 web interface.
Navigate to Configuration > Object > Address / Geo IP Filter.
Click on the Add button to create a new address object.
Enter a name for the address object, such as "Blocked Domains".
Select "FQDN" as the address type.
Enter the domain name(s) that you want to block in the FQDN field. You can enter multiple domain names separated by a space.
Click on the OK button to save the address object.
Navigate to Configuration > Security Policy > Policy Control.
Click on the Add button to create a new security policy.
Configure the source and destination zones and IP addresses as required.
Select the address object that you created in step 6 as the service.
Set the action to "Deny" to block traffic from the specified domain(s).
Click on the OK button to save the security policy.
Configuring FQDN Filtering for Subdomains
To configure FQDN filtering for subdomains, you can use wildcard characters in the FQDN field. For example, if you want to block all subdomains of example.com, you can enter "* .example.com" in the FQDN field. The asterisk (*) is a wildcard character that matches any string of characters.
FQDN filtering is a powerful security feature that allows you to block or allow traffic based on the domain name rather than the IP address. In this article, we have discussed how to configure FQDN filtering on the Zyxel ATP 700, which has a static external IP address and subdomains. By following the steps outlined in this article, you can easily configure FQDN filtering on your Zyxel ATP 700 and improve your network security.
FQDN filtering is a security feature that allows you to block or allow traffic based on the domain name rather than the IP address.
FQDN filtering can be configured on the Zyxel ATP 700, which has a static external IP address and subdomains.
To configure FQDN filtering on the Zyxel ATP 700, you need to create an address object with the FQDN of the domain(s) that you want to block, and then create a security policy that uses the address object and sets the action to "Deny".
To configure FQDN filtering for subdomains, you can use wildcard characters in the FQDN field.
By configuring FQDN filtering on your Zyxel ATP 700, you can improve your network security and block traffic from known malicious websites or domains.
References
/* Example FQDN filtering configuration for Zyxel ATP 700 */
Configuration > Object > Address / Geo IP Filter
----------------------------------------------
Name: Blocked Domains
Type: FQDN
FQDN: example.com google.com
Configuration > Security Policy > Policy Control
------------------------------------------------
Source Zone: LAN
Destination Zone: WAN
Source Address: Any
Destination Address: Any
Service: Blocked Domains
Action: Deny
Schedule: Always