DNS internet filtering solution provides you a configurable dns server. Dns query to a blocked domain will be redirected to a denial page. This solution has below advantages and disadvantages.
- Easier to be deployed. You only need to change your dns server to get filtered.
- Can filter domains via a black list or url category.
- Can provide usage history and reports.
- The filtering dns server may not be as fast as public domain servers.
- Clients can break filtering by modifying dns servers.
- All clients can only share a same blocking policy.
- Can not block applications.
- Can only record dns query quest. No bandwidth reports or visited url reports.
Compared to this internet filtering solutions, WFilter ICF is more difficult to be deployed. However, WFilter is much more powerful:
- When pass-by deployed, WFilter has no influence to your network performance.
- Client can not bypass filtering because WFilter inspects all network packets.
- You can set individual blocking policy for each client.
- More filtering features, including web filtering, web downloading blacklist, url keywords filtering, application control, ip-mac binding…
- More monitoring features and reports. WFilter can record visited domains, url, bandwidth… You can get various reports and statistics.
So if you only need to filter some domains or categories for the whole network, dns filtering would be a good choice. If you need more detailed reports or more dedicated blocking policy, WFilter ICF can be more helpful.