Serve standard DNS clients
Listen for ordinary DNS over UDP and answer from cache or upstream servers, so anything from a PC to a phone can use it as its DNS server.
DNS Proxywall is DNS Firewall and DNS Proxy in one. Run it as a DNS proxy server for other computers on Windows: serve them from a shared cache, build encrypted DNS tunnels between sites, balance upstream servers — and apply your DNS firewall rules to every client behind it.
Point other computers at DNS Proxywall and it becomes their DNS proxy server: it answers from its own cache for speed, forwards what it must to upstream servers, and runs every request through the same DNS firewall rules. Filtering, geo policy and blocking that you configure once protect all of the clients behind it — not just the host machine.
For multiple locations, DNS Proxywall instances can be cascaded: branch resolvers aggregate their DNS traffic into a single encrypted tunnel and forward it to a central instance, where logging and policy live.
Running your own DNS proxy also keeps your network’s DNS private. Instead of pointing every device at an online DNS filtering provider that logs and profiles your traffic, you operate the resolver yourself: the filtering, the policy and the logs stay on your own infrastructure, and you decide which upstream servers — and whether to encrypt the path to them — you trust.
Listen for ordinary DNS over UDP and answer from cache or upstream servers, so anything from a PC to a phone can use it as its DNS server.
Wrap all DNS traffic between two instances into a single TCP tunnel, optionally over SSL/TLS, with mutual certificate verification by SHA-1 thumbprint. SSL/TLS tunnel serving is an Ultimate feature.
Chain instances to centralize DNS, and spread requests across upstream servers with first-server, round-robin, round-robin-on-timeout or concurrent strategies. Slow requests can be auto-blocked.
Authentication is optional. When you need to lock the proxy down, restrict it to specific IP addresses and subnets, and verify tunnel clients by certificate thumbprint. An IP whitelist keeps trusted management addresses always reachable.
Turn on the standard DNS proxy server, and the tunnel listener if you need encrypted site-to-site DNS.
Add upstream DNS servers and choose a load-balancing strategy that fits your reliability needs.
Allow only trusted client IPs and subnets, and require certificate authentication on tunnels.
Add name-pattern and Geo DNS rules once, and every client behind the proxy inherits the policy.
| Need | DNS Proxywall |
|---|---|
| Serve DNS to other computers | Standard DNS proxy over UDP, answered from cache or upstream |
| Encrypt DNS between sites | TCP tunnel, optionally SSL/TLS, with certificate verification |
| Survive a slow or dead upstream | Round-robin and concurrent load balancing, auto-block on timeout |
| Keep the proxy private | IP and subnet authentication plus certificate thumbprints |
| Protect every client at once | Name-pattern and Geo DNS firewall rules apply to proxied traffic |
| Keep your network’s DNS private | You run the resolver — no online filtering provider logs your clients’ queries |
DNS Proxywall can act as a DNS server for other computers on the network. It answers their queries from its own cache or by forwarding to upstream servers, and the same DNS firewall rules apply to that traffic, so every client behind the proxy inherits your filtering policy.
Yes. Two DNS Proxywall instances can connect over a TCP tunnel, optionally wrapped in SSL/TLS, that packages all DNS traffic into a single keep-alive connection. Both sides verify each other’s certificate by SHA-1 thumbprint. SSL/TLS tunnel serving is available in the Ultimate edition.
When several upstream DNS servers are configured, DNS Proxywall applies a load-balancing strategy: first-server-only, round robin, round robin on timeout, or concurrent, where the fastest response wins. Slow requests can be auto-blocked after a timeout.
Authentication is optional and applied only when you turn it on. By default the proxy serves clients without authenticating them, which is fine on a trusted network. When you need to restrict access, it can authenticate proxy clients by IP address and subnet, and tunnel clients additionally by certificate thumbprint. An IP whitelist keeps trusted addresses reachable so rule changes never lock out remote management.
Cache, encrypt and balance DNS for your network — with filtering that protects everything behind it.
Notes:
* Windows® is a registered trademark of the Microsoft Corporation.