4.3.1 Enable Botnet C&C Domain Blocking DNS Filter

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enable Botnet C&C domain blocking to block botnet access at the DNS name resolving stage.

Blocking botnet website access at the DNS resolution stage provides an additional layer of defense.

Solution

On GUI:

1. Go to Security Profiles > DNS Filter.
2. On the relevant security profile name, double click. Enable "Redirect botnet C&C requests to Block Portal".
2. Ensure that firewall policies that have DNS traffic have a DNS Filter security profile applied with that option enabled.

See Also

https://workbench.cisecurity.org/benchmarks/15284