Device-based filtering
Protection sits on the laptop or desktop, so staff stay covered at home, on the road, and in the office. You do not have to rework DNS on every office router.
DNS filtering product brochure
Content filtering that travels with every company device
Layer 3 DNS Guard helps Australian businesses cut web-borne risk: malware and phishing destinations, inappropriate content at work, risky overseas sites, and cloud apps nobody meant to approve. Layer 3 sets the policies, deploys to your devices, and reports in plain language for owners and managers.
There is no storefront pricing on this page. It is a digital brochure so you can see what the platform does before we scope a fit for your sites and staff. Pair it with our cybersecurity services and the DNS filtering guide.
What it covers
Platform strengths
A block list only helps if people can deploy it and keep it current. These are the strengths we build into Layer 3 DNS Guard for Australian offices and hybrid teams.
Protection sits on the laptop or desktop, so staff stay covered at home, on the road, and in the office. You do not have to rework DNS on every office router.
Layer 3 stages and rolls out Layer 3 DNS Guard on your existing endpoints, with as little disruption as we can manage during cutover.
Need to block a category, allow a supplier portal, or lock down a risky site? Policy changes can land quickly so the business is not stuck waiting overnight.
Clear activity and risk reporting for owners, managers, and insurers—readable summaries you can actually use in a meeting.
Spot unusual destinations, shadow SaaS, and habits that deserve a quiet conversation with HR or a manager before they turn into an incident.
For directors & managers
You do not need to be a DNS expert. You need fewer problems on the floor: inappropriate content, malware from a rushed click, public AI tools holding customer data, or cloud apps nobody approved. Here is how Layer 3 DNS Guard shows up in a real office.

Content policy
Inappropriate browsing in an open-plan office is an HR and culture problem as much as a tech one. Category policies block adult and related content on company devices before it becomes a complaint.
Threat blocking
Many attacks start with a link. Filtering stops known-bad and newly weaponised destinations so one curious click is less likely to become a full incident.
AI governance
Layer 3 DNS Guard can block consumer AI sites such as ChatGPT on company devices. Those public chats live outside your encrypted tenant—prompts and uploads can be retained or used by the provider under consumer terms. That makes it easier to keep sensitive work in approved copilots with private, encrypted chats.
Behaviour insight
Analytics flag unusual patterns: repeat hits on blocked categories, odd SaaS tools, or devices that keep testing the edges. Managers can coach early, while the damage is still small.
Device isolation
When one laptop looks compromised, isolation options help limit how far trouble can spread while Layer 3 investigates—without taking the whole site offline overnight.
Geo controls
GeoIP and network controls reduce traffic to regions or networks that have no business talking to your systems.
Company-approved AI
Blocking free AI is only part of the picture. People still need tools that help them write, summarise, and draft. With Layer 3 DNS Guard, Layer 3 can steer traffic toward tools you have approved—such as Microsoft Copilot—where chats sit in your tenant with encryption and commercial data protections.
Type a web address…
Consumer services like ChatGPT are handy, and they are a poor place for business data. Prompts sit outside your encrypted Microsoft (or equivalent) tenancy. Content can be retained, reviewed, or used to improve the product under consumer terms. Filtering those destinations lowers the chance of client files, payroll detail, or strategy drafts ending up in the wrong place.
Point people to Copilot and other company-licensed assistants where conversations stay private to your organisation and fit your security and compliance setup. Layer 3 DNS Guard backs that approach: close the free public path, leave the licensed encrypted path open.
Capability set
Content filtering is the starting point. Behaviour analytics, isolation, GeoIP controls, and SaaS inventory give owners and managers a clearer picture of what is happening on company devices.
Block malware, phishing, and categories you do not want on company devices before the page or app finishes loading.
See how people and apps actually use the internet, so risk shows up in the reports before it catches you by surprise.
Contain a single machine when something looks wrong, while the rest of the office keeps working.
Limit destinations by country or network risk when your industry or insurer expects tighter boundaries.
See which cloud tools staff are really using, so licensing, shadow IT, and compliance talks start with facts.
How it compares
Side-by-side highlights against common DNS filtering products. Open a competitor for the feature table if you already run a legacy filter and want a clearer comparison.
Umbrella is a well-known DNS security product. Layer 3 DNS Guard focuses on device-based filtering so you are not rewriting DNS on every office router, with fast policy updates and behaviour reporting that owners and managers can follow.
| Capability | DNS Guard | Cisco Umbrella |
|---|---|---|
| Device-based filtering without office DNS changes | Yes | No |
| Real-time / near-instant policy updates | Yes | Limited |
| Roaming protection that follows the device | Yes | Yes |
| GeoIP / location-based blocking | Yes | Limited |
| Zero-trust style device isolation | Yes | No |
| User behaviour analytics | Yes | No |
| SaaS inventory and usage visibility | Yes | No |
| Unblock request workflow | Yes | Limited |
Webroot DNS covers basic category and threat filtering. Layer 3 DNS Guard adds behaviour analytics, SaaS visibility, GeoIP controls, and device isolation, so you have more to show a board than blocked categories alone.
| Capability | DNS Guard | Webroot DNS |
|---|---|---|
| Device-based filtering without office DNS changes | Yes | No |
| Real-time / near-instant policy updates | Yes | No |
| Roaming protection that follows the device | Yes | Yes |
| GeoIP / location-based blocking | Yes | No |
| Zero-trust style device isolation | Yes | No |
| User behaviour analytics | Yes | No |
| SaaS inventory and usage visibility | Yes | No |
| Fail-open options that avoid “internet is dead” moments | Yes | Limited |
WebTitan has been around a long time as a DNS filter. Teams pick Layer 3 DNS Guard when they want cleaner deployment, quicker day-to-day changes, and analytics that go past a simple block list.
| Capability | DNS Guard | WebTitan |
|---|---|---|
| Device-based filtering without office DNS changes | Yes | No |
| Real-time / near-instant policy updates | Yes | Limited |
| Roaming protection that follows the device | Yes | Yes |
| GeoIP / location-based blocking | Yes | Limited |
| Zero-trust style device isolation | Yes | No |
| User behaviour analytics | Yes | No |
| SaaS inventory and usage visibility | Yes | No |
| Straightforward admin experience for small IT teams | Yes | Limited |
Quick answers before a discovery call. For the attack types DNS filtering helps with, see the 25 most common cyberattacks.
Tell us about your sites, how people work from home, and any HR or compliance drivers. We will suggest a policy shape and rollout path. Pricing is scoped with you—there is no shopping cart on this page.