Skip to content

Solutions Documentation

Improving App Access Control with DNS Client Query Filtering

Get the latest news, invites to events, and much more

November 3, 2022 |

Access control to applications can be performed at multiple levels in accordance with the security policies in place within the organization. For most, the main level in place nowadays is Authentication and Authorization at the application level through credentials meaning that normally no application is accessible without user screening.


But is that really enough? Can a user with no access to an application get access to the login page? If self registration is not an option for this application, which is mainly the case in organizations, then why expose access to its infrastructure from the network?


There are some very important applications that require specific access and run on a dedicated infrastructure with no sharing of main components. Filtering at the network level is an option to consider, whereby routing access lists and firewall rules are an implicit solution. However, by adding filtering at the DNS level, you raise the security level even higher. This leaves no possibility to resolve the application technical IP addresses, no network level and no credentials, so is a far better approach to security in a Zero Trust environment.


EfficientIP brings this granular network segmentation functionality with its DNS Client Query Filtering (CQF) feature. By having the ability to dynamically update the CQF lists with either application or client entries, security is automatically raised to the appropriate level, limiting the application’s exposure and data visibility to unknown or non authorized users.

Download PDF

Filtering at the DNS level with a DNS Firewall solution is mainly utilized for offering a first line of defense to any kind of user, device and application.

Key Resources

Solutions Documentation
Moving From VitalQIP to EfficientIP DNS-DHCP-IPAM
Explore
Solutions Documentation
Edge DNS GSLB
Explore
Solutions Documentation
Cloud IPAM Sync for Google Cloud Platform
Explore
Migration from Infoblox to Efficientip
Solutions Documentation
Migration from Infoblox to EfficientIP
Explore
Solutions Documentation
Automation Through IT Abstraction Layer
Explore
Solutions Documentation
IPv6 Needs Smart IPAM
Explore
Solutions Documentation
Techniques to Protect Against Data Breaches via DNS
Explore
Solutions Documentation
SOLIDserver IPAM Solutions
Explore
Solutions Documentation
Enhanced DNS Infrastructure Security
Explore
Solutions Documentation
DDI for 5G Infrastructures
Explore