To refine firewall protection, you can create a list of FQDNs to block. Firewall blocks connections to the IP addresses resolving to the domain names.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Firewall from the Products list in the left pane.
From the Category list in the right pane, select Options.
Click the name of an editable policy.
Under DNS Blocking, click Add.
Enter the comma-separated FQDN of the domains to block, then click Save.
You can use the * and ? wildcards. For example, *domain.com.
Duplicate entries are removed automatically.
Note
If the firewall host has not initiated any DNS queries for the blocked domains or FQDN, the DNS blocking and FQDN-based rules do not work.
Click Save.