Skip to content

Solutions Documentation

Improving App Access Control with DNS Client Query Filtering

November 3, 2022 |

Access control to applications can be performed at multiple levels in accordance with the security policies in place within the organization. For most, the main level in place nowadays is Authentication and Authorization at the application level through credentials meaning that normally no application is accessible without user screening.


But is that really enough? Can a user with no access to an application get access to the login page? If self registration is not an option for this application, which is mainly the case in organizations, then why expose access to its infrastructure from the network?


There are some very important applications that require specific access and run on a dedicated infrastructure with no sharing of main components. Filtering at the network level is an option to consider, whereby routing access lists and firewall rules are an implicit solution. However, by adding filtering at the DNS level, you raise the security level even higher. This leaves no possibility to resolve the application technical IP addresses, no network level and no credentials, so is a far better approach to security in a Zero Trust environment.


EfficientIP brings this granular network segmentation functionality with its DNS Client Query Filtering (CQF) feature. By having the ability to dynamically update the CQF lists with either application or client entries, security is automatically raised to the appropriate level, limiting the applicationโ€™s exposure and data visibility to unknown or non authorized users.

Download PDF

Filtering at the DNS level with a DNS Firewall solution is mainly utilized for offering a first line of defense to any kind of user, device and application.

Key Resources

Solutions Documentation

5 Reasons Why EfficientIP DDI Is Better

Explore
Solutions Documentation

EfficientIP for Hybrid Multicloud

Explore
Efficientip and Servicenow Integration Sreamline Workflow
Solutions Documentation

EfficientIP and ServiceNow Integration: Streamline Workflows

Explore
Cover Fortinet
Solutions Documentation

Fortinet and EfficientIP Security Solution

Explore
Solutions Documentation

Zero Trust Security

Explore
360 Dns Security Your First Line of Defense
Solutions Documentation

360ยฐ DNS Security : Your First Line of Defense

Explore
Cisco Meraki Plugin for Cloud Observer Solution Note Cover Page
Solutions Documentation

Cisco Meraki Plugin for EfficientIP Cloud Observer

Explore
Nis 2 Compliance Solutions Overview Cover Page
Solutions Documentation

DDI for NIS 2 Compliance

Explore
Solutions Documentation

Moving From VitalQIP to EfficientIP DNS-DHCP-IPAM

Explore
Solutions Documentation

Edge DNS GSLB

Explore