Create domain lists which will help you build your policy rules. For example, your organization might want a list of social media sites to be used in a block policy, or a short list of sites that point-of-sale machines may access to add to an allow policy. You can also add domain lists to namespaces, as both match and exception lists, to control how queries are forwarded.
BlueCat Threat Protection domain lists
BlueCat also provides a threat intelligence feed called BlueCat Threat Protection. BlueCat Threat Protection includes data from partner feeds, including additional lists curated by the BlueCat internal research team to protect against domains and sites that employ malware, botnets, exploits, and spam. BlueCat Threat Protection domain lists are denoted by the BlueCat Threat Protection <list type>.
- BlueCat Threat Protection High—a list of suspected zones that have been associated with malicious activity within the last 60 days.
- BlueCat Threat Protection Medium—a list of suspected zones that have been associated with malicious activity within the last 60-120 days.
- BlueCat Threat Protection Low—a list of suspected zones that have been associated with malicious activity exceeding 120 days.
- BlueCat Threat Protection Unverified—a list of possible suspected zones that have not yet been reviewed and classified.
- BlueCat Threat Protection DoH Public Servers—a list public servers known to perform DNS resolution over HTTPS (DoH).
Adding a new domain list
- In the top navigation bar, click
and select Domain Lists.
- Click New to create a new domain list, or select an existing domain list and click Edit.
- Enter the domain list name.
- Enter a brief description of the domain list.
- Choose one of the following ways to add domain names to the list:
- To add domains individually, type the name into the
Domains field (for example
www.bluecatnetworks.com) and press Enter.
Individually added domains appear below the Domains field. If you enter a domain that's already in the list, it will be highlighted in the list to show you where the item is.
To remove a domain from the list, click the X beside its name.
- Drag and drop a .csv or text file of domains into the field, and click
Save to upload the file.
The domain list file must contain one domain per line and must be in plain text format. When uploading a .csv file, each domain in the list must be in the first column of the line.
You can't edit a list of more than 2000 entries, but you can override the entries with a new list, or type /clear to start again.
Lists under 2000 items will be visible for editing.
- To add domains individually, type the name into the
Domains field (for example
www.bluecatnetworks.com) and press Enter.
- If you want to download a copy of the domain list, click
Download, choose a folder in which to save the file, and
click Save.
To delete a domain list, select it and click Delete. If a domain list is associated with a namespace or policy, you must remove it from the namespace or policy before you can delete it.
Note: You can't edit, download, or delete the BlueCat Threat Protection domain lists. - Click Save.
- When you build a block policy, you can add domain lists of exceptions. Creating a primary domain list of exceptions and adding it to your block policies lets you regain access to a domain that has been erroneously blocked.
- You can clear all items from a domain list, including an attached file, by typing /clear in the domains field.
- Attaching a file using drag-and-drop overrides all of the items currently in your list.
- For easy management, you can download a copy of your domain list using the icon in the top right.
- If you edit a domain list that's associated with a namespace, and the edits cause the number of domains in the list to exceed 100,000, you won't be allowed to save your changes.
- If you are importing a BlueCat Integrity response policy list, the
*.example.comand**.example.comdomains will be converted to just the domain names in upon import in Edge.