Product
Web filtering | Browsing control on the endpoint
Filtering runs on the computer itself, so it protects the user wherever they are: at the office, at home or connected from a hotel.
KairosLink resolves the computer's DNS queries against per-category lists and blocks whatever the policy says. The categories available today are malware and phishing, adult content, gambling and social media. On top of that come each organization's own hand-loaded lists of blocked and allowed domains.
Each customer has a base policy and as many additional policies as needed. Additional policies are assigned to a specific computer, an Active Directory security group or an Organizational Unit, with an explicit precedence order: first the computer, then the group, then the Organizational Unit, and finally the base policy. There is never a computer without a policy.
The agent downloads the policy and the lists, and from then on resolves on its own. If it loses connection with the panel, it keeps enforcing the last policy in effect. The policy can also be set to block the DNS over HTTPS services browsers use to sidestep the filter.
Every block is logged and the report shows the most blocked domains and categories, with filters by period and by customer.
What it filters and what it does not
Whole domains are filtered, not individual URLs. With HTTPS the rest of the address travels encrypted, so you can block an entire site but not a specific section of that site.
Filtering is not traffic inspection: the content of the user's communications is never opened or read.
If the agent stops for any reason, the computer recovers its original DNS configuration and keeps browsing. We prefer a customer without a filter to a customer without internet.
The computer's Active Directory domain and KairosLink's infrastructure are never filtered, even if they showed up on a list by mistake.
Web filtering is available on the Business and Enterprise plans.
Frequently asked questions
What is DNS web filtering?
Can I block a whole category?
Can the user bypass it by switching browsers?
Does it help enforce acceptable use policies?
Does it apply to every computer equally?
Do I need to install extra hardware on the customer's network?
Does it work if the user takes the laptop home?
What happens if the computer loses connection with the panel?
Can I block a specific section of a site?
Can I apply a different policy per area of the company?
What happens if the agent stops working?
All modules included. No credit card.