How to block DNS queries using App Control Advanced

Description

The App Control Advanced signatures for DNS includes country code top-level domains, DNS queries and responses and a signature to block the new .xxx top level domain. A SonicWall administrator can choose to enable these signatures in any of the following methods:
Block the whole DNS application group, which will block all DNS queries passing through the SonicWall.
Block individual signatures.  For Example, .cn to block China domains; .xxx to block adult entertainment domains.

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.


  • Login to the SonicWall Management GUI.
  • Navigate to Policies | Security Services | App Control | Status/Settings page.
  • Enable the check box under Enable App Control and Accept.
  • On Signatures tab, select PROTOCOLS under Category.
  • From the drop down under Application, select DNS Protocol.
  • Set Viewed by to Signature.
    Image

    Image

Blocking Individual signatures:

  • Click on the Configure button on the signature you wish to block. In this example, we have chosen Standard Query .xxx Adult Entertainment Domains -SID 6821.
  • In the Edit App control signature window set Enable under Block and Log.
  • Click OK to save the settings.
    Image

Blocking DNS Application group:

  • Click on the Configure icon under Application with DNS selected.
  • In the App Control App Settings Window, select Enable under Block and Log.
  • Click OK to save.
    ImageImage


Enabling Application Control on Zones:

  • Navigate to Objects |Match Objects | Zones.
  • Click on Configure button on the Zone on where you want to enable Application Control.
  • Enable Application Control Service.
  • Click Save to save settings.
    Image

Logging

DNS queries from behind the SonicWall will be blocked and log messages will be generated under Monitor | Logs | System Logs

Image

Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.


  • Login to the SonicWall Management GUI.
  • Navigate to the Firewall | App Control Advanced page.
  • Check the box under Enable App Control  and click on the Accept button at the top to enable App Control.
  • Under Manage | Rules | App Control select PROTOCOLS under Category; select DNS Protocol under Application; select Signature under Viewed By, to list the signatures available under this application:
Image

Blocking individual signatures

  • Click on the configure icon of a signature you wish to block. In this example, we have chosen Standard Query .xxx Adult Entertainment Domains - SID 6821.
  • In the Edit App Control Signature window, select Enable under Block and Log.
  • Click on OK to save.
Image

Blocking DNS application group

  • Click on the configure icon under Application with DNS selected.
  • In the Edit App Control App window, select Enable under Block and Log.
  • Click on OK to save.Image


Image

Enabling Application Control on zones

  • Navigate to Manage | Network | Zones
  • Click on the configure button under the zone where you want enable App Control.
  • Check Enable App Control Service.
  • Click on OK to save.

Image


Logging

DNS queries from behind the SonicWall will be blocked and log messages similar to the following will be generated under Investigate | Event Logs  
 
Image

Resolution for SonicOS 6.2 and Below

The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.


  • Login to the SonicWall Management GUI.
  • Navigate to the Firewall | App Control Advanced page. 
    NOTE: In Gen5 Tz devices this page is under Security Services | App Control 
  • Check the box under Enable App Control  and click on the Accept button at the top to enable App Control.
  • Under App Control Advanced | View Style select PROTOCOLS under Category; select DNS under Application; select Signature under Viewed By, to list the signatures available under this application:
Image


Blocking DNS application group

  • Click on the configure icon under Application with DNS selected.
  • In the Edit App Control App window, select Enable under Block and Log.
  • Click on OK to save.
Image


Blocking individual signatures

  • Click on the configure icon of a signature you wish to block. In this example, we have chosen Standard Query .xxx Adult Entertainment Domains - SID 6821.
  • In the Edit App Control Signature window, select Enable under Block and Log.
  • Click on OK to save.
Image


Blocking a country code top-level domain

  • Click on the configure icon of a signature you wish to block. In this example, we have chosen Standard Query .cn China Domains - SID 6822.
  • In the Edit App Control Signature window, select Enable under Block and Log.
  • Click on OK to save.
Image

Enabling Application Control on zones

  • Navigate to Network | Zones
  • Click on the configure button under the zone where you want enable App Control.
  • Check Enable App Control Service.
  • Click on OK to save.

Image


Logging

DNS queries from behind the SonicWall will be blocked and log messages similar to the following will be generated under Log | View:
 
Image

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?