DNS & SASE

VeraDNS product overview

6 min readDNS & SASE

VeraDNS is an on-premise DNS firewall and filtering platform that inspects every DNS query on your network and blocks malware, phishing, ransomware and command-and-control domains the moment they are requested — before a single connection is made. Built for organisations that demand full data sovereignty, it runs entirely on your own infrastructure with no endpoint agents to deploy.

Protective DNS, on your own infrastructure

Unlike cloud DNS services, VeraDNS resolves and filters DNS within your perimeter. Deploy it via Docker, point your network's DNS to it, and every device — PCs, servers, IoT and OT — is protected from a single resolver. Because DNS queries, policy data and audit logs never leave your environment, VeraDNS suits regulated industries and sensitive networks where data residency is non-negotiable.

Key features

  • Network-wide filtering for every device from one resolver, with zero agents.
  • Real-time threat intelligence — auto-updating blocklists covering malware, phishing, ransomware and C2.
  • Encrypted DNS — standard DNS, DoH, DoT, DoQ and DNSSEC validation.
  • Programmable policy by category, client group or time window.
  • Role-based access control with API-level enforcement and full audit logging.
  • One-click compliance reports mapped to NIST 800-53, CIS v8, ISO 27001 and NCSC.
  • SIEM and REST API export to Splunk, Microsoft Sentinel and Elastic.

Vera Insight: live visibility

VeraDNS includes the Vera Insight console, which turns raw queries into live visibility — a risk-posture score, allowed-versus-blocked metrics, a real-time query stream with domain, client, type and latency, a world-map threat landscape, and resolver-health monitoring. Because it all runs locally, security teams get full telemetry for threat hunting without sending data to a third party.

Fast to deploy, simple to run

VeraDNS is designed to be live in under an hour: deploy the container, update one DNS setting, and protection begins. Minimum requirements are modest — a couple of vCPUs and a few gigabytes of RAM — and high availability is achieved by running multiple resolver instances behind a load balancer. Licensing is tiered by query throughput and user scale, so it fits a single site or a large enterprise.

Where it fits

Protective DNS is one of the most cost-effective layers in a defence-in-depth strategy. VeraDNS complements next-generation firewalls and endpoint protection by neutralising threats at the request stage, covering devices that cannot run agents, and giving SOC teams rich query telemetry. For multi-site and branch networks, a single resolver protects every device without deploying software to each endpoint.

How iconnet helps

iconnet supplies, deploys and supports VeraDNS for organisations across Thailand. We size the deployment, configure policy and integrations, and support it through its lifecycle. Contact us for a demonstration or a free trial on your own infrastructure.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.