What is DNS Firewall

更新时间:
复制 MD 格式

DNS Firewall secures DNS resolution across Public Zone, Private Zone, HTTPDNS, and self-managed DNS—from public internet to private intranet, cloud to on-premises.

Features

Private Zone DNS Firewall

Private Zone DNS Firewall secures Private Zone. When a VPC application queries external domains through Private Zone, integrated threat intelligence identifies and blocks malicious domains—phishing, ransomware, and trojans—in real time.

image

Public Recursive DNS Firewall

Public Recursive DNS Firewall protects queries sent to Recursive Gateway and HTTPDNS. Once enabled, integrated threat intelligence identifies and blocks malicious domains—phishing, ransomware, and trojans—in real time.

image

Public Zone DNS Firewall

Alibaba Cloud DNS provides DDoS mitigation for Public Zone. Self-managed authoritative services can use an authoritative proxy for enhanced security, faster resolution, disaster recovery, and high availability.

image

Benefits

  • High-precision threat intelligence

    The Private Zone DNS Firewall and Public Recursive DNS Firewall integrate 600,000+ threat intelligence entries across 60+ threat types—phishing, trojans, ransomware, and more—to block malicious access.

  • Visual protection analytics

    The Private Zone DNS Firewall and Public Recursive DNS Firewall provide real-time visual analytics on malicious domain detection and blocking, including trends, flagged domains, and threat categories.

  • Unified, full-link protection

    Combine the Private Zone DNS Firewall, Public Recursive DNS Firewall, and Public Zone DNS Firewall for end-to-end DNS query protection across internal and external networks with centralized management.

Scenarios

Component

Application Scenario

Scenario Description

Private Zone DNS Firewall

Internal endpoint security

Blocks malicious domains at the DNS layer for corporate intranet devices, preventing risks from user errors like clicking phishing links.

Unified protection for cloud VPCs and self-managed data centers

For hybrid cloud or multi-data-center enterprises, the Alibaba Cloud Private Zone DNS Firewall covers cloud VPCs and on-premises environments with consistent security policies.

Sensitive data protection

Prevents data theft and leakage in high-security industries (finance, healthcare) by blocking access to malicious domains.

Custom security policies

Create custom mitigation policies and integrate third-party threat intelligence for industry-specific security needs.

Public Recursive DNS Firewall

Malicious domain name blocking

Blocks malicious domain queries in real time, preventing access to phishing sites and malware distribution points.

Internet access security

Secures daily internet access for enterprises, reducing incidents from employee errors like clicking unknown links.

Compliance support

Helps enterprises meet network security compliance requirements and strengthen protection.

Security enhancement for open source DNS

Enterprises using open-source DNS can connect to the Alibaba Cloud Public Recursive DNS Firewall for malicious domain detection and blocking.

Public Zone DNS Firewall

Public DDoS attack mitigation

Provides DDoS mitigation for domain names hosted on Public Zone.

Security for self-managed DNS

Protects self-managed DNS from DDoS attacks and accelerates resolution through an authoritative proxy.

Billing

Billing for DNS Firewall varies by feature and usage. Billable features include the Private Zone DNS Firewall and Public Recursive DNS Firewall. Usage is metered by query count or number of protected VPCs/domain names. Pay-as-you-go and subscription billing are both supported. Product billing.

FAQ

Find answers in the DNS Security FAQ.