Solutions
Home & FamilyBusinessMSP / MSSP
Tools
Domain CheckerDNS Leak TestThreat Intel
Company
PricingGuidesDocsAboutContact
Home / Guides / Firewall setup

Set up DNS filtering on your firewall or router.

Covering a whole office usually means changing one setting: the DNS servers your network hands out. Here is where that setting lives on the most common firewalls.

Set up · Updated September 30, 2026 · 8 min read

In shortRegister your office's public IP in DNSAFE, then set your DHCP server to hand out 3.12.124.91 (primary) and 3.11.62.44 (secondary). If you run Active Directory, leave clients on your domain controllers and add those two addresses as forwarders instead. Menu names change between firmware versions, so treat the paths below as a guide.

Before you start

  1. Find your public IP. Visit dnsafe.net/myip from the office network.
  2. Register it. In the DNSAFE portal, add the IP to your network. DNSAFE identifies your network by the public IP your lookups come from, so lookups from unregistered addresses are refused. If your ISP changes your IP from time to time, register the range it uses, or ask for a static IP.
  3. Note the resolver addresses:
    UseAddress
    Primary DNS3.12.124.91 (US)
    Secondary DNS3.11.62.44 (UK). Same filtering, used if the primary can't be reached
    By name (nearest region)resolver.dnsafe.net
    DNS-over-TLS / DNS-over-HTTPSdns.dnsafe.net (port 853) / https://dns.dnsafe.net/dns-query

Windows Server and Active Directory

If your computers use domain controllers for DNS, don't point them straight at DNSAFE, or internal names like fileserver.corp.local will stop resolving. Filter the internet lookups at the domain controller instead:

  1. Open DNS Manager, right-click the server and choose Properties.
  2. On the Forwarders tab, remove existing forwarders and add 3.12.124.91 and 3.11.62.44.
  3. Untick Use root hints if no forwarders are available, or failed lookups will skip the filter.
  4. Repeat on every domain controller that runs DNS.

Logs will show your office's public IP rather than each PC. That's expected, because the domain controller makes the lookups on the PCs' behalf.

FortiGate (FortiOS)

  1. Go to Network → Interfaces and edit the LAN interface.
  2. Under DHCP Server → DNS server, choose Specify and enter the primary and secondary addresses.
  3. Optionally, set the FortiGate's own resolvers in Network → DNS to the same addresses if clients use the FortiGate as their DNS.
  4. Click OK. Clients pick up the change when they renew their lease; reconnecting or running ipconfig /renew speeds that up.

Cisco Meraki MX

  1. Go to Security & SD-WAN → Configure → DHCP.
  2. For each VLAN, set DNS nameservers to Specify nameservers… and enter the two addresses, one per line.
  3. Click Save.

Ubiquiti UniFi

  1. In the UniFi Network app, go to Settings → Networks and select the network.
  2. Under the DHCP settings, turn off automatic DNS and enter the two addresses as DNS Server 1 and 2.
  3. Apply, then repeat for guest and other networks.

pfSense and OPNsense

  1. Go to Services → DHCP Server (on newer pfSense, DHCP Server under the interface), choose the LAN interface and enter the addresses under DNS servers.
  2. If clients use the firewall's own resolver, go to Services → DNS Resolver and enable forwarding mode, then add the two addresses under System → General Setup → DNS Servers.
  3. Save and apply.

SonicWall (SonicOS)

  1. Go to Network → DHCP Server and edit the LAN scope.
  2. On the DNS/WINS tab, choose to specify DNS servers manually and enter the two addresses.
  3. Optionally, set the same addresses under Network → DNS.

Any other router

Look for the DHCP or LAN settings and a field called DNS server, primary DNS or name server. Enter the two addresses there, not in the WAN or internet settings, which only affect the router itself.

Try DNSAFE on your own network: 14 days free, no card, set up in minutes.

Start free trial

Check that it's working

  1. On a computer in the office, run nslookup example.com. The server shown should be one of the DNSAFE addresses (or your domain controller).
  2. Run the DNS leak test. It should show DNSAFE as your resolver.
  3. Open the DNSAFE portal: lookups from your office should appear in the logs within a minute or two.

Then close the bypass routes

Devices with hard-coded DNS, browsers with their own encrypted DNS, and VPN apps can skip the settings above. Add a firewall rule so only your DNS servers can make outbound DNS queries, and turn off browser DoH by policy: see how to stop DNS filtering bypass.

Frequently asked questions

Should I set DNSAFE as primary and my ISP's DNS as secondary?

No. Devices use the secondary DNS whenever they like, not only when the primary fails, so an unfiltered secondary lets lookups skip filtering. Use both DNSAFE addresses.

Do I need to restart every computer?

No. Devices pick up the new DNS servers when their DHCP lease renews. To speed things up, reconnect Wi-Fi or run ipconfig /renew on Windows.

What if my office has a dynamic IP address?

DNSAFE recognizes your network by its public IP. If yours changes, register the range your ISP uses for your connection, or ask your ISP for a static IP, which most business plans include.

Protect every device on your network.

Point your router or firewall at DNSAFE. 14 days free, no card.