Configuring Anti-Bot & Advanced DNS Settings
Configuring Anti-Bot & Advanced DNS Settings
How to Configure Anti-Bot and DNS Settings
In the profile settings, go to Anti-Bot & Advanced DNS Settings.
In the General section, configure the Anti-Bot UserCheck Settings:
- Prevent - Select the UserCheck message that opens for a Prevent action
- Ask - Select the UserCheck message that opens for an Ask action
Configure Advanced DNS Settings
Enable/Disable Advanced DNS features:
- DGA (Domain Generation Algorithm) - This feature detects domains generated by a DGA, mainly used for C&C communication of malware.
- DNS Tunneling (domain name based) - The feature detects DNS tunnels that use domain names to transfer data.
- NXNS Attack Detection - This feature detects whether the DNS replies exhibit behavior consistent with NXNS Attack.
Protocol related features:
- DoH (DNS over HTTPS) - Allows the inspection of DoH traffic. This requires enabling HTTPS Inspection on the Security Gateway. The feature supports both RFC 8484 and non-RFC variants.
Configuring a Malware DNS Trap
The Malware DNS trap works by configuring the Security Gateway to return a false (fabricated) IP address for known malicious hosts and domains.
- Do not use a gateway address that leads to the internal network.
- Do not use the gateway internal management address.
- If the gateway external IP address is also the management address, select a different address for the DNS trap.
You can also add internal DNS servers to better identify the origin of malicious DNS requests. Using the Malware DNS Trap, you can detect compromised clients by checking logs with connection attempts to the false IP address.
At the Security Gateway level, you can configure the DNS Trap according to the profile settings or as a specific IP address for all profiles on the specific gateway. Malware DNS Trap supports only IPv4.
| Step | Instructions |
|---|---|
| 1 | In SmartConsole, select Security Policies>Threat Prevention. |
| 2 | From the Custom Policy Tools section, click Profiles. The Profiles page opens. |
| 3 | Right-click the profile, and click Edit. |
| 4 | From the navigation tree, click Malware DNS Trap. |
| 5 | Click Activate DNS Trap. |
| 6 | Enter the IP address for the DNS trap. |
| 7 | Optional: Add Internal DNS Servers to identify the origin of malicious DNS requests. |
| 8 | Click OK and close the Threat Prevention profile window. |
| 9 | Install the Threat Prevention policy. |
| Step | Instructions |
|---|---|
| 1 | In SmartConsole, click Gateways & Servers and double-click the Security Gateway. The gateway window opens and shows the General Properties page. |
| 2 | From the navigation tree, select Anti-Bot and Anti-Virus. |
| 3 | In the Malicious DNS Trap section, select one of these options: |
- According to profile settings - Use the Malware DNS Trap IP address configured for each profile.
- IPv4 - Enter an IP address to be used in all the profiles assigned to this Security Gateway. | | 4 | Click OK. | | 5 | Install the policy. |
Note - If you create an Exception which disables Anti-Bot for specific sources, the DNS Trap feature is not disabled. To disable DNS Trap for specific sources, create a new Threat Prevention profile for these sources with DNS Trap disabled.
17 June 2026