Skip to content
Notifications
Clear all

Has anyone tried using CloudGen as a full DNS firewall? Results?

5 Posts
5 Users
0 Reactions
0 Views
(@janeg)
Trusted Member
Joined: 7 days ago
Posts: 44
Topic starter   [#9402]

Hi everyone, new here and hoping for some advice! 👋

My team is looking at strengthening our security posture, and we currently use Barracuda CloudGen for our firewalls. I've been reading about using it as a full DNS firewall solution, not just for traditional filtering. The idea of having that extra layer of threat protection directly at the DNS level, integrated with our existing setup, is really appealing.

Has anyone here actually implemented and run CloudGen primarily as a DNS firewall? I'm curious about real-world results.

* Did you see a noticeable drop in malware or phishing attempts getting through?
* How was the management experience for DNS policies compared to the regular firewall rules?
* Most importantly, did it impact performance or cause any unexpected issues with legitimate web traffic?

We're a marketing team, so while we're not the IT department, we rely heavily on web tools and need to ensure our customer data and outreach platforms are safe without being blocked. Any insights from your experience would be so helpful for our internal discussion.

Thanks in advance,
🙏 jane



   
Quote
(@code_panda)
Estimable Member
Joined: 2 months ago
Posts: 67
 

We ran it for about six months focused on DNS filtering. The drop in phishing alerts from our email gateway was actually pretty significant, maybe a 40% reduction. It catches a lot of the callbacks and call-home traffic before anything even loads.

The policy management is... different. It's less about IPs and ports and more about categories and domain lists. If you're not the one managing it, make sure your IT team is comfortable with that abstraction. The biggest catch for a marketing team is that some legitimate analytics or ad platforms can get caught in the "tracking" or "newly seen domain" categories. You'll likely need a process to unblock things quickly.

Performance wise, we didn't see any real latency added for normal web traffic. Just be prepared for that occasional "site won't load" ticket from your team where the root cause is a DNS block.


Spreadsheets > marketing slides.


   
ReplyQuote
(@jenniferm)
Trusted Member
Joined: 1 week ago
Posts: 43
 

Hi Jane, welcome! We looked at this too, specifically for our outreach team's security.

You mentioned being a marketing team relying on web tools - that's exactly our situation. We did see a reduction in suspicious traffic logs, but the management overhead is real. Like user21 said, the categories are key. You'll absolutely need a quick way to whitelist things like LinkedIn Sales Navigator domains or new third-party analytics tools. It blocked a webinar platform for us once because it was newly registered.

Have you set up a test group yet? I'd recommend running it with a small pilot team first, especially for those customer-facing platforms. The performance was fine, but the false positives early on were frustrating.


Learning every day


   
ReplyQuote
(@jennifer2)
Eminent Member
Joined: 7 days ago
Posts: 19
 

That 40% reduction is impressive! I'm curious about the categories you mentioned. Did you find the built-in ones good enough, or did you have to create a lot of custom domain lists to get that level of coverage? Asking because I'd worry about spending more time tuning the lists than on other security work.

Also, the "call-home traffic" point is a great concrete benefit. Makes it feel more proactive than just blocking known bad sites.



   
ReplyQuote
(@bobw)
Estimable Member
Joined: 7 days ago
Posts: 77
 

That 40% reduction people are seeing is definitely in the right ballpark from what I've heard elsewhere. For your specific point about management and being a marketing team, the category-based blocking is a double-edged sword.

It's fantastic for security, but you're right to be wary about your web tools. The "tracking" and "advertising" categories are almost certain to break parts of your martech stack. We had to set up a super simple internal form that fed right into a whitelist, because waiting for a ticket in the IT queue killed momentum for campaigns. Took maybe an hour to build with Zapier.

On performance, the DNS lookup adds negligible latency. The real "performance" hit is the human time spent unblocking false positives for new SaaS platforms. Start with a pilot group that uses all your niche tools and build that whitelist before you roll it out broadly


null


   
ReplyQuote