DNS filtering product brochure

Layer 3 DNS Guard

Content filtering that travels with every company device

Layer 3 DNS Guard helps Australian businesses cut web-borne risk: malware and phishing destinations, inappropriate content at work, risky overseas sites, and cloud apps nobody meant to approve. Layer 3 sets the policies, deploys to your devices, and reports in plain language for owners and managers.

There is no storefront pricing on this page. It is a digital brochure so you can see what the platform does before we scope a fit for your sites and staff. Pair it with our cybersecurity services and the DNS filtering guide.

What it covers

  • Content & threat filtering
  • Behaviour analytics
  • Isolated devices
  • GeoIP filtering
  • SaaS inventory & usage

Platform strengths

Seamless integration

A block list only helps if people can deploy it and keep it current. These are the strengths we build into Layer 3 DNS Guard for Australian offices and hybrid teams.

Device-based filtering

Protection sits on the laptop or desktop, so staff stay covered at home, on the road, and in the office. You do not have to rework DNS on every office router.

Easy to deploy

Layer 3 stages and rolls out Layer 3 DNS Guard on your existing endpoints, with as little disruption as we can manage during cutover.

Fast policy updates

Need to block a category, allow a supplier portal, or lock down a risky site? Policy changes can land quickly so the business is not stuck waiting overnight.

Powerful reporting

Clear activity and risk reporting for owners, managers, and insurers—readable summaries you can actually use in a meeting.

Risky behaviour analytics

Spot unusual destinations, shadow SaaS, and habits that deserve a quiet conversation with HR or a manager before they turn into an incident.

For directors & managers

What risk reduction looks like in a real office

You do not need to be a DNS expert. You need fewer problems on the floor: inappropriate content, malware from a rushed click, public AI tools holding customer data, or cloud apps nobody approved. Here is how Layer 3 DNS Guard shows up in a real office.

Reporting overview
Layer 3 DNS Guard reporting dashboard showing top websites, categories, and active time trends

Content policy

Stop NSFW content at work

Inappropriate browsing in an open-plan office is an HR and culture problem as much as a tech one. Category policies block adult and related content on company devices before it becomes a complaint.

Threat blocking

Cut phishing and malware clicks

Many attacks start with a link. Filtering stops known-bad and newly weaponised destinations so one curious click is less likely to become a full incident.

AI governance

Restrict free public AI tools

Layer 3 DNS Guard can block consumer AI sites such as ChatGPT on company devices. Those public chats live outside your encrypted tenant—prompts and uploads can be retained or used by the provider under consumer terms. That makes it easier to keep sensitive work in approved copilots with private, encrypted chats.

Behaviour insight

See risky behaviour early

Analytics flag unusual patterns: repeat hits on blocked categories, odd SaaS tools, or devices that keep testing the edges. Managers can coach early, while the damage is still small.

Device isolation

Contain a problem machine

When one laptop looks compromised, isolation options help limit how far trouble can spread while Layer 3 investigates—without taking the whole site offline overnight.

Geo controls

Tighten where traffic can go

GeoIP and network controls reduce traffic to regions or networks that have no business talking to your systems.

Company-approved AI

Keep staff productive with company-approved AI

Blocking free AI is only part of the picture. People still need tools that help them write, summarise, and draft. With Layer 3 DNS Guard, Layer 3 can steer traffic toward tools you have approved—such as Microsoft Copilot—where chats sit in your tenant with encryption and commercial data protections.

Search Google or type a URL

Type a web address…

Public AI stays off company devices

Consumer services like ChatGPT are handy, and they are a poor place for business data. Prompts sit outside your encrypted Microsoft (or equivalent) tenancy. Content can be retained, reviewed, or used to improve the product under consumer terms. Filtering those destinations lowers the chance of client files, payroll detail, or strategy drafts ending up in the wrong place.

Approved AI with encrypted private chats

Point people to Copilot and other company-licensed assistants where conversations stay private to your organisation and fit your security and compliance setup. Layer 3 DNS Guard backs that approach: close the free public path, leave the licensed encrypted path open.

  • Encrypted chats inside your licensed tenant
  • A clear list of approved AI tools on every device
  • Fewer accidental uploads of customer or HR data to public AI

Capability set

Filtering, visibility, and control in one place

Content filtering is the starting point. Behaviour analytics, isolation, GeoIP controls, and SaaS inventory give owners and managers a clearer picture of what is happening on company devices.

Content & threat filtering

Block malware, phishing, and categories you do not want on company devices before the page or app finishes loading.

Behaviour analytics

See how people and apps actually use the internet, so risk shows up in the reports before it catches you by surprise.

Isolated devices

Contain a single machine when something looks wrong, while the rest of the office keeps working.

GeoIP filtering

Limit destinations by country or network risk when your industry or insurer expects tighter boundaries.

SaaS inventory & usage

See which cloud tools staff are really using, so licensing, shadow IT, and compliance talks start with facts.

How it compares

Layer 3 DNS Guard versus common alternatives

Side-by-side highlights against common DNS filtering products. Open a competitor for the feature table if you already run a legacy filter and want a clearer comparison.

Layer 3 DNS Guard vs Cisco UmbrellaFeature table

Umbrella is a well-known DNS security product. Layer 3 DNS Guard focuses on device-based filtering so you are not rewriting DNS on every office router, with fast policy updates and behaviour reporting that owners and managers can follow.

CapabilityDNS GuardCisco Umbrella
Device-based filtering without office DNS changesYesNo
Real-time / near-instant policy updatesYesLimited
Roaming protection that follows the deviceYesYes
GeoIP / location-based blockingYesLimited
Zero-trust style device isolationYesNo
User behaviour analyticsYesNo
SaaS inventory and usage visibilityYesNo
Unblock request workflowYesLimited
Layer 3 DNS Guard vs Webroot DNSFeature table

Webroot DNS covers basic category and threat filtering. Layer 3 DNS Guard adds behaviour analytics, SaaS visibility, GeoIP controls, and device isolation, so you have more to show a board than blocked categories alone.

CapabilityDNS GuardWebroot DNS
Device-based filtering without office DNS changesYesNo
Real-time / near-instant policy updatesYesNo
Roaming protection that follows the deviceYesYes
GeoIP / location-based blockingYesNo
Zero-trust style device isolationYesNo
User behaviour analyticsYesNo
SaaS inventory and usage visibilityYesNo
Fail-open options that avoid “internet is dead” momentsYesLimited
Layer 3 DNS Guard vs WebTitanFeature table

WebTitan has been around a long time as a DNS filter. Teams pick Layer 3 DNS Guard when they want cleaner deployment, quicker day-to-day changes, and analytics that go past a simple block list.

CapabilityDNS GuardWebTitan
Device-based filtering without office DNS changesYesNo
Real-time / near-instant policy updatesYesLimited
Roaming protection that follows the deviceYesYes
GeoIP / location-based blockingYesLimited
Zero-trust style device isolationYesNo
User behaviour analyticsYesNo
SaaS inventory and usage visibilityYesNo
Straightforward admin experience for small IT teamsYesLimited

Common questions

Quick answers before a discovery call. For the attack types DNS filtering helps with, see the 25 most common cyberattacks.

Will Layer 3 DNS Guard slow our internet?
Filtering at the DNS / connection layer adds a small check before a site or app connects. Most people never notice it. If something feels off, we walk the path with you and fix it.
What happens if someone tries to open inappropriate content at work?
Category policies can block adult and related content on company devices. The user sees a block (or the app fails to connect). Reports can show patterns so HR and managers have solid facts when those conversations come up.
Does it protect staff working from home?
Yes. Because protection is device-based, filtering travels with the laptop when Layer 3 deploys Layer 3 DNS Guard. Home and office both stay covered.
Does Layer 3 DNS Guard replace antivirus or our firewall?
No. It sits alongside endpoint protection, email filtering, and firewalls. Each layer catches different risks. See how it fits our cybersecurity work.
Can managers see exactly which websites people visit?
Reporting is configurable. We help you set retention, who can view logs, and how much detail is appropriate for Australian privacy expectations and your HR policy. The aim is risk reduction and clear accountability.
How does Layer 3 deliver Layer 3 DNS Guard?
We design policies with you, deploy to devices, tune false positives, and report on a cadence that suits owners and managers. For a plain-English primer, read DNS content filtering for Australian businesses.

Ready to look at Layer 3 DNS Guard for your business?

Tell us about your sites, how people work from home, and any HR or compliance drivers. We will suggest a policy shape and rollout path. Pricing is scoped with you—there is no shopping cart on this page.