Skip to content →
Log in

Secure Web

Filter web destinations on traffic routed through PulseHA.

Secure Web filters host and domain destinations. It is separate from private DNS service discovery.

Configure filtering#

  1. Open Security → Secure Web and enable content filtering in Settings.
  2. Create domain lists for reusable allow, deny, or bypass hosts.
  3. Create an ordered policy and add category, domain, or domain-list rules.
  4. Choose the default action and enable the policy.
  5. Route applicable internet traffic through a PulseHA exit path.
  6. Review decisions in Security → Audit under Content Filter.

Enter hosts or domains, not full URLs. URL path must not be relied on as an enforceable filter boundary. Linux agents do not receive explicit proxy configuration, so do not assume web-proxy inspection from agent enrollment alone.

DNS filtering can be bypassed by public encrypted DNS unless DoH and DoT controls are enabled. A compilation warning means gateways may continue using the previous ruleset.

Use DNS for names assigned to private services.