Solutions
Comprehensive DDI security with 21+ integrated modules including SWG, GSLB and DHCP Security. Every module built with enterprise needs in mind.
DNS Security
Firewall Policies
Granular DNS filtering with drag-and-drop rule ordering, schedule-based activation (day/time/timezone), multi-source matching (IP/CIDR/GeoIP/Source Groups), category & domain list targeting, risk score thresholds, and routing policies.
Secure Web Gateway (SWG)
Cloud-delivered Secure Web Gateway with HTTPS/SNI inspection, URL category enforcement, application control (social, streaming, gaming, AI tools), TLS fingerprinting, file-type blocking, SafeSearch enforcement, custom block pages, and per-user/per-group policy chains — all inheriting from the same DNS firewall rule engine for unified Zero Trust web access.
Domain Lists
Whitelist/blacklist management with built-in presets (social media, streaming, gaming, adult, gambling, advertising), bulk import, category tree integration, per-entry tracking, and export capabilities.
Domain Categories
AI-powered automatic categorization with 120+ categories, confidence scoring (High/Medium/Low), risk assessment (Safe to Critical), manual override support, wildcard domain search, and source tracking (AI/Manual/Cache).
WHOIS Records
Domain intelligence with age analysis (very-new/new/mid/old), expiry tracking with color-coded alerts, DNSSEC validation, registrar info, raw WHOIS data display, and automated refresh cycles.
Source Groups
Network source management with IP address, CIDR range, and IP range entries. Bulk import, per-entry descriptions, policy assignment integration, and flexible grouping for organizational network segments.
DNS Simulator
Visual policy evaluation simulator with source node info (domain, categories, risk score), step-by-step rule flow showing hit/skip status, source/domain/category/risk micro-dot matching, and final verdict (Allowed/Blocked/Redirected).
Network Management
DNS Servers
Multi-region DNS server management grouped by geography (8 regions), health monitoring with latency classification (fast/medium/slow/very-slow), auto-discovery, selective server activation, and online/offline status tracking.
DNS Zones
Full DNS zone management with 5 zone types (Primary/Secondary/Forward/Stub/Reverse), 14+ record types, AXFR/IXFR import with TSIG authentication, BIND/CSV import-export, zone cloning, agent assignment with DNS-Only mode, and SOA timer configuration.
GSLB — Global Server Load Balancing
Geo-aware DNS load balancing with health-checked pools (HTTP/HTTPS/TCP/PING monitors), weighted round-robin, failover, geo-proximity routing, latency-based selection, member health dot indicators in record content, custom monitor intervals/timeouts, and automatic NXDOMAIN protection — turning your DNS into a high-availability global traffic manager.
DHCP Server
Built-in enterprise DHCP server with subnet/scope management, pool ranges, gateway/DNS configuration, static reservations, active lease monitoring (active/declined/expired), VLAN support, and migration from ISC/Windows/MikroTik/CSV.
DHCP Security
Enterprise-grade DHCP threat protection: MAC fingerprinting & device classification, OUI vendor identification, MAC spoofing detection, rogue DHCP server detection, DHCP starvation attack mitigation, MAC blacklist/whitelist enforcement, fingerprint stale-after-lease cleanup, and per-scope security toggles — protect your network at Layer 2 before clients ever resolve a domain.
IPAM
IP Address Management with visual IP grid (color-coded: Active/DHCP/Reserved/Rogue/Inactive), auto-scanning at configurable intervals, rogue device detection, IP history tracking, device type classification (server/workstation/printer/IoT), and capacity planning.
Monitoring & Admin
Dashboard
Real-time monitoring with 9 stats cards, traffic charts (Allowed/Blocked), top domains & clients analysis, WebSocket live updates, queries-per-minute tracking, and quick-access shortcuts to all modules.
Defenders
Endpoint DNS agent management with approval workflows, compliance checks, automatic heartbeat monitoring, version tracking, OS/architecture info, and instant config sync across all deployed agents.
Log Analyzer
Real-time DNS log analysis with WebSocket live streaming, wildcard search, multi-filter support (domain/action/source/type/date), query type badges (A/AAAA/CNAME/MX/TXT), latency color coding, and detailed rule match modal.
Users / Computers
Network client management with DHCP source integration, LDAP computer sync, per-client analytics links, vendor identification, MAC address tracking, and OS detection.
Alarms
Threshold-based alerting with 7 alarm types: domain match, frequency, blocked threshold, new client, category, new domain, and DNS tunnel detection. Severity levels (info/warning/critical) with status workflow (open/acknowledged/resolved).
Audit Log
Comprehensive admin action logging with CREATE/UPDATE/DELETE/LOGIN/LOGOUT tracking, resource type filtering, user agent recording, IP address logging, JSON detail view, and filtered export to JSON.
Reports
Automated reporting with 3 types (General/Security/Performance), multiple formats (CSV/JSON/PDF), scheduled generation (daily/weekly/monthly), preview stats with top domains/clients, and full report history with status tracking.
Administration
System management with Users/Roles/Permissions RBAC, LDAP/AD integration with SSO, SIEM/Syslog forwarding, system backup, SMTP mail configuration, DNS resolver settings, customizable block page, and comprehensive audit logging.
