Partners









Public Instructions PDF Print E-mail

ThreatSTOP operates by providing multi-host Fully Qualified Domain Name forward (A record) lookups. Each lookup resolves to up to 4000 IP addresses.

To use ThreatSTOP block lists, you configure rules that reference the block list, and take the desired action.

Due to the size of the lists, you will need to allow TCP queries from your Firewall/Nameservers.

 

To use the lists, you use the list in place of the IP address in your rule or object configuration on your firewall.

The specific mechanism for doing this varies by device, but the general form of the rules is:

FROM basic.threatstop.com TO ANY DENY

FROM basic1.threatstop.com TO ANY DENY

FROM basic2.threatstop.com TO ANY DENY

FROM basic3.threatstop.com TO ANY DENY

FROM basic4.threatstop.com TO ANY DENY

 

FROM ANY TO basic.threatstop.com DENY

FROM ANY TO basic1.threatstop.com DENY

FROM ANY TO basic2.threatstop.com DENY

FROM ANY TO basic3.threatstop.com DENY

FROM ANY TO basic4.threatstop.com DENY

 

Specific instructions for how to install threatstop with our private service are here . The only difference when using the public service is that you don't need to change your nameserver, and you use threatstop.com as the domain, instead of threatstop.local.

 

With the public DNS we cannot guarantee that all the lists will propagate correctly, due to limitations of some nameservers, and the possibility of cache poisoning. That is why we created our service as a private, secure DNS.