QS-WAN · Name resolution

DNS filtering that follows the VLAN, not the building

DNS filtering blocks a site by refusing to look up its name. In QS-WAN you build a profile from nine blocking categories, switch on safe search, and assign it to a VLAN. Everyone on that segment gets it, wherever they are working today.

What it is

What a DNS profile is, and where it lands

Most filtering of this kind lives on the office router. It works well right up until somebody picks up the laptop and leaves the building, which is the entire reason they were given a laptop. The second half of the problem is that the box holds one list. Finance, the warehouse tablets, the guest network and the contractor who is here for three weeks all get the same rules, because there is nowhere else to put them. So the list gets loosened until nobody complains, and a list nobody complains about is not filtering much.

The profile, built once

Nine blocking categories: adult content, gaming, general interest, time stealers, cyber threats, business, consuming, drugs and aggressive content. Safe search is a switch on the same screen, not a separate product you go and buy.

The segment it lands on

You assign the profile to a VLAN, and that is the part worth slowing down for. A VLAN here is a segment you define in software, with its own address space and its own rules about what it can reach. The finance segment is a real object with a real boundary, not a colour on a diagram somebody drew in 2019.

The few minutes it takes

Changes reach people who are already connected within a few minutes. Not instantly. We would rather write that here than write immediately and let you find out the difference on a Tuesday morning.

What you want is a different answer per segment, applied wherever those people are working today. That is the whole of it.

The mechanism

Five requests, one laptop, and the one that never asks for a name

Switch the profile and watch which names stop resolving. Then watch the fifth request, the one written as an address, go through on every profile. That is the honest shape of a name control, and it is in the drawing rather than in a footnote.

crm.acme.combusinessnews-daily.examplegeneral interestbet-live.examplegamingc2-node.examplecyber threats198.51.100.24no name askedDNS profileFinance1 category blockedof nineFinance VLANthe profile is assigned herehistory: offskips the lookup
3 of 4 names resolved

Five requests leave the same laptop. Four of them ask for a name: crm.acme.com, news-daily.example, bet-live.example and c2-node.example. The fifth opens a socket straight to 198.51.100.24 and never asks for anything. On the Finance profile only cyber threats are blocked, so three of the four names resolve. Warehouse tablets also block gaming and general interest, so only crm.acme.com resolves. Guest blocks cyber threats and gaming, so two resolve. On all three profiles the request to 198.51.100.24 goes through, because it skipped the lookup and never met the profile.

Why this exists

Four things that go wrong without it

The control stops at the front door

A filter on the office box is running on the days people are in the office. Every remote day is a day you are paying for a control that is not switched on for the person who needs it.

One list has to satisfy four different groups

Finance, the warehouse tablets, the guest network and a three-week contractor share the box, so they share the list. It gets loosened until the complaints stop.

Nobody can say what a segment is allowed to look up

Per department is a claim until it is a screen. A profile, the VLAN it is assigned to, and the query history behind it turn the claim into a record.

The laptop in the bag comes back on old rules

A machine that has been shut since Thursday picks up the new profile when it reconnects, not before. If you did not know that, you were counting a control you did not have.

What you get

One profile, two people who care about it for different reasons

The person running the network wants a different answer per segment. The person signing for it wants to know what gets ripped out, and the answer is nothing.

For the network

One list per segment, not one per building

You write a profile for finance and another for the warehouse tablets instead of loosening the only list you have until nobody complains.

No ticket to touch a laptop

The profile arrives through the connection the device already has. Nobody drives to a site, and nobody talks somebody through changing a resolver over the phone.

A history you can actually read

Your control server collects the queries and the console reads them back. It is the screen you open when you need to know what a machine was asking for at three in the morning.

For the business

Nothing gets ripped out

The router stays, the line stays, the firewall stays. There is no cutover weekend to budget for and no hardware to decommission.

Policy that survives the laptop leaving

The rule is attached to the segment, not to the address of an office, so it is still running in a hotel lobby on a Wednesday.

An answer when somebody asks how access is restricted

You show the profile, the VLAN it is assigned to, and the query history if collection is on. A record instead of a description of an intention.

How it works

Three steps, and nobody has to touch a laptop

The laptop connects, and the filter comes with it

The person opens the QNova Client and works. They are not asked to pick a resolver, and there is no profile switcher on the device, because the profile for their VLAN rides the connection. From their side the whole experience is that certain names do not resolve, and that is the design working rather than a support ticket. A filter that asks the user to agree with it is a suggestion.

You get the half of the story they do not have

The person at the keyboard knows one page did not load. You get the queries, from your control server, in the QS-WAN console, for machines that are nowhere near your office. That is the context the device cannot give you, and it is the difference between somebody saying the internet is weird and knowing which machine asked for what, and when.

You change one profile, and the segment changes with it

Now the decision is yours to make in one place. Tighten a category for the segment that needs it, leave the other segments alone, and the change reaches everyone already connected in a few minutes. Nobody was asked to do anything, which is the point: there are not eleven people to chase about a setting they cannot see anyway.

Before you start

You need the segments you already run and the client your people already have. There is no appliance to rack and nothing extra to install, because the profile travels on the connection.

In detail

The lists behind the categories, and the log you can switch off

Lists

What is behind the nine categories

The categories are backed by domain feeds held in the platform. Counted on 2 September 2026, those feeds held 4,817,815 domains across the nine lists.

That is the size of the lists. It is not a count of anything blocked, and we are being fussy about the distinction on purpose, because those two numbers get printed as though they were the same one. They are not, and only one of them is measurable. Profiles can be created, assigned and deleted one at a time or in bulk, and the bulk part sounds like a detail until the week you inherit somebody else naming scheme.

History

The query log, and the switch that turns it off

The control server collects a history of DNS queries and the console reads it back. Collection is a toggle, so you decide whether it runs at all. Before you turn it on, the console warns you about ingestion volume, and it is right to. DNS is chatty: one busy laptop produces more lookups in an afternoon than most people would guess, and a few hundred laptops turn that into a storage decision.

Turn the toggle off and the collection stops filling. Nobody here is watching your queries either: this is a product you run, not a monitoring service we sell. The history lives on your control server and it is read in your console, by your people.

Where this earns its place

Four mornings this changes

The contractor who is here for three weeks

They go on their own segment with their own profile, and the finance list does not have to be loosened to accommodate them. When they leave, the segment goes with them.

The warehouse tablets that only need four things

A tight profile on that VLAN, and the tablets stop being general-purpose internet devices that happen to scan barcodes. Nothing changes on any of them.

Somebody asks what a machine was talking to at 03:40

You switch collection on, and from then on that question has an answer in the console rather than a shrug. Switch it off again and it stops filling.

Half the company is working from home on Wednesday

The profile is attached to the segment, so it is running in fourteen living rooms exactly as it runs at a desk. There is no in the office version of the rule.

Works better with

What it sits next to, and why each one matters

A profile attaches to a VLAN, so the segments have to exist before the profile has anywhere to land. This is where the boundaries get drawn.

Names are one control. Addresses, ports and hours are the other, and that is the one that meets the request which skipped the lookup.

The same connection, read for throughput instead of for names. Useful the moment the question turns from what was asked to how much moved.

A name that resolves is just a name that resolves. Stopping a file once it is on the disk is a different mechanism, and it lives here.

What this does not do

The limits, because they are what make the rest believable

It does not stop a connection that never asks for a name

Anything that opens a socket straight to an address has skipped the lookup, so it never meets the profile. That is the fifth request in the diagram above, and it goes through on every profile. A name control is a name control.

It does not inspect files

A name that resolves is just a name that resolves. Stopping a malicious file once it is on the disk is the endpoint side of the product, a different mechanism with different evidence behind it.

It is not instant, and a saved change is not proof

The console records your intent reliably. Getting that intent out to gateways and devices is best effort, so a laptop shut in a bag since Thursday picks up the new profile when it comes back, not before.

It does not send your queries anywhere near us

The history lives on your control server and is read in your console, by your people. This is a product you run, not a monitoring service we sell, and if you would rather it did not exist at all, the toggle is right there.

Questions people ask

The ones that come up first

What is DNS filtering?

DNS filtering blocks a website by refusing to look up its name. Every device that wants to reach a site first asks a resolver to turn the name into an address, and the filter sits at that step and declines to answer for names on a blocked list. In QS-WAN you build that list from nine blocking categories, add safe search if you want it, and assign the result to a VLAN.

Does it still work when the laptop leaves the office?

Yes. The profile is attached to the VLAN and reaches the device through the QNova Client connection, not through the office router, so a laptop in a hotel gets the same profile as the same laptop at a desk. Changes you make take a few minutes to reach people who are already connected.

Can somebody change the resolver on their own laptop?

The QNova Client does not ask them to, and it does not offer a profile switcher on the device. What they can see, if they open the connection details, is which DNS server the tunnel is using, next to the negotiated cipher suite, the tunnel address, the public address, the adapter type and the link speed. That is a read-out, not a control panel.

Does DNS filtering stop malware?

No. It is a name control, so it only meets traffic that asks for a name first, and anything that opens a socket straight to an address has skipped the lookup. It does not inspect files either. Stopping a malicious file once it is on the disk is the endpoint side of the product, and that is a different mechanism.

Who can read our query history?

Your people, in your console. The history is collected by your control server and read in QS-WAN, and nobody here runs a monitoring service over it. Collection is a toggle, so if you would rather it did not exist at all, you turn it off and it stops filling.

How many domains are on the lists?

Counted on 2 September 2026, the nine feeds held 4,817,815 domains. That is the size of the lists and not a count of anything blocked. The two numbers get printed as though they were the same one, and only one of them is measurable.

Tell us which segment you would tighten first.

You say how your network is split and which group you would lock down on Monday. We build that profile on screen, assign it to the VLAN, and open the query history so you can see exactly what it records and what it does not. It is free and there is nothing to sign.

Scroll to Top