Cisco
Overview
If you have not yet registered for the service, you can do so by visiting our registration page. Connect to the control panel by entering the Cisco IP address in the address bar of any browser. Then, log in by entering your administrative credentials.
Configure the Device DNS
First, you need to configure the DNS of the device. To do this, open the Setup menu and then click on Network.
Look for the section called WAN Setting Table and select the exact name of your WAN interface. Click on the Edit button to modify the interface parameters.
In the window that appears, enable the Use the Following DNS Server Address item and then type the following cloud IPs inside the DNS Server 1 and DNS Server 2 fields respectively:
- DNS Server 1: 185.236.104.104
- DNS Server 2: 185.236.105.105
Click on the Save button to save the changes.
Configure Dynamic DNS Service
To configure the Dynamic DNS service, open the Setup menu and then click on Dynamic DNS. Select the name of your WAN interface again and click on Edit.
Configure the service exactly as follows:
- Service: Select DynDNS.org.
- Username: Enter the specific username assigned to your dynamic network inside our dashboard. Do not use your main registration email.
- Password: Enter the specific password assigned to your dynamic network.
- Host Name: Enter the address link.
Finally, click Save to make the changes active.
Enable the DHCP Server
At this point, you can enable the DHCP Server so that it automatically assigns network parameters, including our filtered DNS, to the various internal devices.
Open the DHCP menu and click on DHCP Setup. Configure the service with your local network parameters and select Use DNS as Below next to the DNS Server field to configure our cloud addresses.
Then enter the following IPs in the Static DNS fields:
- Static DNS 1: 185.236.104.104
- Static DNS 2: 185.236.105.105
Finally, click Save to activate the service. Alternatively, the DNS settings of the various devices within the network can be changed manually one by one.
Optional: Deny DNS Changes by Users
It is possible to increase security by denying users the ability to browse unfiltered by manually changing the DNS on their local devices. To do this, open the Firewall menu and click on Access Rules. Then click on Add to create a new rule.
At this point, we need to create rules to block all outbound traffic on port 53 for the DNS Service on both TCP and UDP protocols, except for requests directed specifically to our cloud IPs.
Rule A: Allow Primary DNS
Proceed as follows to create the first rule:
- Action: Choose Allow.
- Service: Select the DNS entry UDP port 53 to 53 from the drop-down menu.
- Log: Decide whether or not you want to display the log related to this rule.
- Source Interface: Select the name of your internal LAN interface.
- Source IP: Choose ANY.
- Destination IP: Select Single and then enter the IP 185.236.104.104 in the field on the right.
It is also possible to select a specific IP range that will use this rule instead of applying it to the entire network.
Click Apply to save.
Rule B: Allow Secondary DNS
Now it is necessary to create another rule exactly similar to the previous one, except for the Destination IP field address, which must be 185.236.105.105.
Rule C: Block All Other DNS
Finally, it is necessary to create a drop rule to block all DNS traffic directed to external IPs other than our own. Proceed as follows:
- Action: Choose Deny.
- Service: Select the DNS entry UDP port 53 to 53 from the drop-down menu.
- Log: Decide whether or not you want to view the log related to this rule.
- Source Interface: Select the name of your internal LAN interface.
- Source IP: Choose ANY.
- Destination IP: Select ANY from the drop-down menu.
Then click Save to apply the final changes.