Subscribed blocklists
Point Cloud DNS at any published blocklist by its URL. The platform fetches it and keeps it refreshed, so a list you trust stays current without anyone re-uploading it.
Cloud DNS turns a Sign In Enterprise network into a managed, filtering resolver. Block the domains you don't want, always allow the ones you do, and shape it with rulesets you apply to the whole network or a single site, on a schedule. Delivered through your Service Gateway, with nothing to run on site.
Every network on Sign In Enterprise already sends its DNS somewhere. Cloud DNS replaces that plain forwarding with a resolver you control. Instead of every lookup passing straight through, each one is checked against the policy you set. Is this domain on a list you block? Is it one you always allow? Does a ruleset cover this part of the network, at this time of day? Then it resolves, or it does not.
You compose that policy from a few simple parts: blocklists you subscribe to, blocklists you build yourself, and allowlists that always take precedence. Rulesets tie them together and decide who they apply to and when.
A blocklist is just a list of domains, so it can carry any policy you can name, not only malware and adult content. Subscribe to a published list, write your own, or generate one with AI for exactly what you want off the network: the streaming and social domains that turn a parking or transit network into a hangout, say. The policy is yours to define.
A ruleset takes the lists you chose, subtracts the domains you always allow, and lands on one clear result: the effective list, the exact set of domains this policy blocks. Add who it applies to and when, and the whole policy fits on a card.
No guesswork about what a rule really does. You can download the effective list a ruleset resolves to and see every domain in it.
Point Cloud DNS at any published blocklist by its URL. The platform fetches it and keeps it refreshed, so a list you trust stays current without anyone re-uploading it.
Build named lists of the domains you want gone, by hand or by bulk import. A blocklist is just domains, so it can hold any policy you can name, not only security categories. Wildcards cover a domain and everything under it.
Some domains must always resolve: your payment provider, your booking system, your own services. Allowlisted domains override every blocklist.
Point an internal hostname straight at an IP. Handy for on-site services that never make it into public DNS.
Apply a ruleset across the entire network, or scope it to the sites you choose. One network, different policy where it needs to differ.
Give a ruleset a weekly schedule when you only want it active during certain hours, in your own timezone. Leave the schedule off and it applies around the clock.
A bad domain that never resolves can never load. Subscribe to security and tracker lists and every device on the network is covered, with nothing to install.
Free Wi-Fi at a parking garage, a charging point or a transit stop should let people pay, verify with their bank app and be on their way, not become somewhere to stream and scroll all day. Allow the domains the network exists for; block the ones that turn it into a hangout.
Filter distractions during school or work hours and lift the policy after. One ruleset, a weekly schedule, no switch to flip by hand.
Run a tighter policy at one site and a looser one at another from the same place, by scoping rulesets to the sites they belong to.
DNS filtering is a sharp, low-cost layer. Knowing exactly where it stops is part of using it well.
Cloud DNS is an add-on to Sign In Enterprise, not a standalone product. It uses the same organizations, sites and roles you already manage.
Your Service Gateway points the network at Cloud DNS. Cisco router as Service Gateway and Cisco SD-WAN are both supported.
Pick your lists, build a ruleset, choose where and when it applies, and turn the network from plain DNS to Cloud DNS. Changes take effect on the network as you make them.
The captive-portal service Cloud DNS is an add-on to. Onboarding, sites and roles all come from here.
Read moreThe integration that carries a network to Netgraph. It is what routes DNS to Cloud DNS in the first place.
How it connectsThe service description: what it filters, how rulesets resolve, and what your network needs to provide.
Read the docsCookies help us improve this site. With your consent we also measure how it is used, with our own analytics and Google Analytics, configured with no advertising or cross-site tracking. Read our Privacy Policy for more.
When you visit our website it may store or retrieve information in your browser, mostly as cookies. This information is used to make the site work as you expect and, with your consent, to understand how it is used. Because we respect your privacy, you can choose not to allow some cookies. Note that blocking some of them may affect your experience.
These cookies are needed for the website to function and cannot be switched off. They are usually set only
in response to actions you take, such as signing in to internal areas or filling in a form. They store no
information that identifies you personally (cookie: ng_learn_session).
With your consent, we measure how the site is used: unique and returning visitors, approximate city and
region, time on a page, and entry and exit pages. This runs on our own first-party cookies
(ng_consent, ng_vid, ng_sid) and on Google Analytics
(_ga), configured so Google gets no advertising or cross-site signals. We never store your IP
address. If you do not allow this, we use only privacy-friendly, cookieless measurement.