Information
Enable Botnet C&C domain blocking to block botnet access at the DNS name resolving stage.
Rationale:
Blocking botnet website access at the DNS resolution stage provides an additional layer of defense.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
On GUI:
1. Go to Security Profiles > DNS Filter.
2. On the relevant security profile name, double click. Enable 'Redirect botnet C&C requests to Block Portal'.
2. Ensure that firewall policies that have DNS traffic have a DNS Filter security profile applied with that option enabled.
Default Value:
'Redirect botnet C&C requests to Block Portal' is enabled on default profile.