Welcome to the DNS Protection Discussion Forum!
Recently active
For many years, DNS was mainly seen as a basic networking service: a way to translate domain names into IP addresses. But the latest NIST SP 800-81r3 Secure DNS Deployment Guide makes it clear that DNS should now be treated as a critical part of the security architecture.Why? Because almost every internet connection starts with DNS.Before a user visits a website, before an application connects to a cloud service, and before malware reaches out to command-and-control infrastructure, a DNS request usually happens first. That makes DNS one of the earliest and most effective places to detect, block, and investigate suspicious activity.Protective DNS as a Security ControlNIST highlights the importance of Protective DNS as part of a modern defence-in-depth and zero trust strategy. Protective DNS can help reduce exposure to phishing, malware, ransomware, and command-and-control traffic by applying security policy at the point of domain resolution.In simple terms, if a user or device tries to
Hey everyone,I recently tried downloading Jenny’s Mod, and while the website works perfectly, I ran into a few network security concerns on my PC:🔹 Firewall Blocking Downloads – My security settings flagged the download, even though I trust the source. Is there a way to whitelist safe game files without turning off my antivirus completely?🔹 Slow Download Speeds – The site itself is fast, but my network seems to throttle downloads for some reason. Could this be a DNS or ISP-related issue?🔹 VPN Causing Installation Errors – When I use a VPN, the game doesn't install properly. Could this be related to how my PC handles network connections?I want to make sure I’m setting everything up securely without affecting performance. Has anyone else faced similar issues with game downloads & security settings?Edit: Link Removed. (PTD)
The feedback we received from the previous beta was foundational to its success – to the extent that we did not receive one bug complaint or call to Support indicating a problem!! This community is truly awesome! – Thank you!Further feedback mentioned that the previous beta was challenging to participate in as you needed either a trial of DNS Protection or an active Webroot Management Console. We hear you! With this next beta, this time, no Keycode will be required! Simply download and use the Beta Runner! However, if you prefer to use a Keycode you already have, it can be specified.Why a second beta?No software should ever stand still, it must evolve and progress! The second release of DNS Leak Prevention has some awesome new features that further augment Leak Prevention; namely, we have added the ability to dynamically detect DoH servers! Whereas previously we leveraged BrightCloud to provide an up-to-date list, now that is just the foundation to build on - now new DoH servers are de
We are very pleased to announce the launch of the DNS Leak Prevention Beta. This is an opportunity for us to share with you the feature we are about to release, as well as to solicit feedback, both from a technical and functionality perspective. Download the Beta Runner (link removed)Documentation available (link removed) What is DNS Leak Prevention? This is a new patent pending feature of the Webroot DNS Protection product. It is designed to provide control of DNS by blocking all alternate DNS resources aside from those configured in Webroot DNS Protection. This is done by locking down port 53 TCP and UDP (DNS), port 853 TCP (DNS over TLS), and port 443 TCP to known DoH providers. Why are we creating DNS Leak Prevention? As Webroot DNS Protection is a DNS filtering product, if we are not filtering every DNS request, it means that things are being missed. For example, if a web browser were to be configured to get DNS resolution directly from its own server, and disregard what was confi
Hi Team,anyone has any experience implementing DNS protection for users who use VPN (Point-to-site). In my case, it is bypassing the DNS filtring after the VPN gets connected. Tried to play with protected networks feature but no luck. Any experience, tip or advice would be welcome.We have mixture of Azure p2s and Sonicwall global VPN client, both bypass DNS agent.
Hello forum members,I hope everyone is doing well. Today, I would like to discuss an issue I've been encountering regarding the compatibility between Webroot DNS Protection and our web filtering software. If any of you have experienced similar challenges or have insights to share, I would greatly appreciate your input.The Challenge:Compatibility between Webroot DNS Protection and Web Filtering SoftwareAs an organization, we understand the importance of web filtering [ https://lenovonetfilter.com/resource/five-common-web-filtering-questions-answered ] to ensure a safe and secure online environment for our users. We have been using a web filtering software solution to control internet access and block inappropriate content. Recently, we implemented Webroot DNS Protection to enhance our overall security measures. However, we have encountered some compatibility issues between these two solutions.Specifically, we have noticed the following challenges:Conflict between Webroot DNS Protection
Hello, after i enable webfoot DNS and create dns protection policy i just check social networking , when i apply this policy to site pc’s can not access gmail from any browser what is the reason of it ??
Hi, I tried to enable DNS protection for a macOS device (v10.15.3 Catalina). I noticed there is only a Windows icon on “Install DNS Protection” settings. Does this mean DNS protection is not yet supported on macOS? I checked the docs but couldn’t find anything about this. Is there a way to manually install the DNS protection agent if it is not possible via the policy settings? Thanks for any help.
Hi Where do you manage DNS Protection now in the new console including reports? Thanks
The block page category function does not work for uncategorized sites. The user and tech had no idea why the page is being blocked. On that if a URL does not resolve there should be a Category as well. People will typo URLs and think the page is blocked when it is just them going to the wrong place.
Hi All – I am the Product Manager for DNS Protection and my colleague @JonathanB and I are resident DNS evangelists and we are always interested in hearing from you on your experience with the product – good or bad! It has been close to 2 years since we launched DNS Protection service to the market and I am happy to share that we received the highest rating by Expert Insights and we are seeing good steady adoption of the product. Webroot is committed to serving our SMB and MSP customers and bringing best in class Security offerings. To recap, 2018 was a very busy year for us and I would like to highlight some key product enhancements that has driven our growth: VPN support + IPv6 support (only vendor to support IPv6 for roaming clients) Granular Policy Management enables support at Site, Group, and individual devices. Stable, Hardened DNS client for roaming devices. Powered by BrightCloud Threat Intelligence – Quality, Brand and Accuracy providing Real Time Threat
I need to block all websites except for six that are allowed on the computers. This is a very locked down environment. I don’t see a way to block “ALL websites” and only allow just a handful. wildcards do not work thanks
Hello all,I saw a few other forum posts about this topic with no replies.When an offsite domain workstation connects to our VPN, all of the webroot DNS filters are overwritten and they can access any website. When disconnected from the VPN, the web filter takes effect again almost immediately.We plan to take a look on our end with the firewall, but wanted to bump this question since it seems to be a popular one and I wasn’t sure if anyone has come across a solution.Thank you!
For home-based teleworkers (in particular) who do not have a hardware firewall doing SSL/TLS Deep Packet Inspection, does Webroot DNS Protection mitigate most of the threats that TLS Inspection would likely catch?
Really need a sanity check. Getting ready to deploy DNS protection to a client that only has endpoint protection.The only difference between this client and other using DNS protection is that they don’t have a DNS server. They have no on-prem servers or services that would need to resolve locally. Storage and apps are cloud based.I couldn’t find anything in the deployment guides about anything different for this type of environment. I suspect it is because there is nothing different that needs to be done, but I thought I would reach out to the community pre-deployment to see if anyone has deploy to a similar environment recently and what to expect.TIAMike
Hi, We're currently running a demo of the DNS Protection agent. So far, I like the ease of install; just enable it on the Webroot SecureAnywhere Endpoint Policy and it gets installed pretty much immediately (next poll). That's nice. Also like the DNS protection at the network level - guest wifi, DNS forwarders. So anything devices on the network get the benefit as well. What I'm not liking is the reporting. There's no way to do a custom report on a user's web browsing. And there's no DNS Charts for the Dashboard. It would be nice to quickly look at the Dashboard and see some charts for Web Browsing - Top Users, Threats Blocked, etc. We're currently a Forcepoint shop and potentially looking to switch Are there any Reporting updates coming soon to this product? Thanks.
We have to big issue in Turkey to use Dns Protection. In the starting of computers Dns Protection agent cannot resolve any websites like 5 minutes. After 5 minutes Dns agent working properly. This is a very big issue, a lot of customers, and potential customer affected from that problem.
Can anyone tell me where I should make new DNS protection policies? If I go to the larger policies at the top, these don’t show up in DNS protection. If I go to the cog for DNS protection, you can only choose a policy for the site as a default. If I go into the client this is to manage Endpoint Protection. We have a customer, say “steve inc” for example, I need half to have one DNS policy but the other half another, it would seem this is impossible?
Hi Everyone, My name is Kiran Kumar and I am the Product Director for Network portfolio within the business segment – responsible for DNS-Protection and FlowScape - Network Anomaly detection. I am based in sunny San Diego and have been with Webroot for 4yrs driving various network and Threat Intelligence portfolio. Complementing our award winning Endpoint Protection product, we have put a layered approach in protecting our SMB and MSP clients with a network based solution called DNS-Protection. This is a compelling advantage for Webroot as we look to further establish ourselves as a security leader in the MSP/SMB market and provide a comprehensive security solution and be the trusted security advisor for our MSP/SMB community. Our approach to product development is to bring incremental releases to market and making adjustments based on customer needs and you can find highlights from most recent DNS-P release here. I am excited to be the featured PM for this
When using Webroot DNS, we have to refresh to get web pages to open. If we switch to Google DNS servers, web pages open up without issue. Any ideas
I find webroot Google search engine. I hope you will help. I am teacher in the school. I need to block this site. I give you link. https://sites.google.com/site/allunblockedgames77 Children enter this site in their free time. They don't listen to me. Can I block through the system, will you show me the way ? I want to block all unblocked games web site. I try dns but it is useless. Thank you.
We've had issues when connecting to Wi-Fi where it shows that we have no internet even though we are connected to the wireless network. We've only seen this issue start after implementing Webroot DNS. Anyone else having this?
I'm trying to get webroot to report the following, but I haven't found a report that does this yet. I need to see a report that ONLY shows me websites a user has actually typed into the browser, I don't need to see every bit of communication between the client and the webroot DNS servers. I need to see exactly what time in my own time zone, PST, not UTC when the user accessed each website. I need to see how long a user has actually been on a website. For example, I want to see two different times, one for active website, and then if a user just has the website open, but hasn't touched it for 2 hours, let's say the tab is open in the browser, I want to see the difference between the two. Is there such a report, or can a report please be written to show the above info, as the current reports are useless to me.
I'm not sure if this is appropriate in the community forums, but I was hoping someone could test my DNS settings and verify if they are experiencing the same issue (if this is not appropriate, any troubleshooting tips would be greatly appreciated). I've attached screenshots of my DNS Policy and Web Allow List. We have a need to occasionally place orders on the site: https://suzannesomers.com, but when attempting to progress past the Customer Information page, nothing happens. There is no blocked page, and the site does not forward any DNS queries that I could see by using the nirsoft DNS sniffer tool. Here is how to recreate the issue we are experiencing. On the website after a few moments there will be some scrolling products, hover over the picture> Quick View> Add to Bag. Then new the top right of the page is the Cart icon, click the icon and then click Checkout. From here there are two URLs that you could be forwarded to (I have not been able to determine what
The current customization options for the DNS block page is a little lacking. We added a mailto link in the page to send an email to request a site be unblocked/updated. This goes to our ticketing system. The issue though is that many end users forget to put in the site they need unblocked, so it creates additional overhead in reaching out to the end user to find out which site it is that needs to be corrected. (Most of the time, the site is just categorized incorrectly.) Is there any way to get this information available or to edit the customization text as HTML instead of a WYSIWYG text editor? If we could edit as HTML I could add in a tiny javascript tag that would pull the address and incorporate that into the mailto link so we would always have the correct site that needs to be unblocked.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.