> ## Documentation Index
> Fetch the complete documentation index at: https://docs.goguardian.com/llms.txt
> Use this file to discover all available pages before exploring further.

# DNS Precision Filtering

> How DNS Precision Filtering extends GoGuardian DNS with subnet-based rules and Agent Awareness for on-premise Windows Server networks.

DNS Precision Filtering extends GoGuardian's DNS filtering so you can differentiate rules by subnet and private IP address. It runs as the GoGuardian DNS On-Prem application, a Windows service installed locally on a Windows Server.

Once installed, DNS Precision Filtering supports filtering by IP address and Agent Awareness, which recognizes when a device has a GoGuardian agent installed (the GoGuardian extensions or The GoGuardian App) and bypasses DNS filtering for that device.

This article covers the DNS Precision Filtering feature set. It does not include installation steps. To get started, contact your GoGuardian Account Manager.

## Add Subnet Filtering

Once the GoGuardian DNS On-Prem application is installed, you can add subnets from the **Subnets** tab of any network.

1. Click **Add Subnet**.
2. In the **Name Subnet** section, enter a name for the subnet.
3. In the **Add Private IP Address Ranges** section, enter a **Start IP Address** and **End IP Address**, then click **Add IP Range**. Repeat for each additional range.
4. In the **Assign Policies** section, enter a policy name and click **Assign Policy**.

<img src="https://mintcdn.com/goguardian/XFzHF494idV3Fqar/images/screenshots/dns-precision-filtering/step-02.png?fit=max&auto=format&n=XFzHF494idV3Fqar&q=85&s=4e15a0c106964e0bd028e8216d2a43a9" alt="Add Subnet panel showing the Name Subnet field and Add Private IP Address Ranges section" width="1546" height="884" data-path="images/screenshots/dns-precision-filtering/step-02.png" />

<img src="https://mintcdn.com/goguardian/XFzHF494idV3Fqar/images/screenshots/dns-precision-filtering/step-03.png?fit=max&auto=format&n=XFzHF494idV3Fqar&q=85&s=e008055760dec7939840e7f8bf21b96d" alt="Assign Policies section of the Add Subnet panel" width="866" height="504" data-path="images/screenshots/dns-precision-filtering/step-03.png" />

## Enable Agent Awareness

Agent Awareness is an optional feature that bypasses network-level filtering in favor of filtering by organizational unit (OU). It keeps DNS filtering in place for guests, personal devices, and BYOD environments without affecting users who already have the GoGuardian extensions or The GoGuardian App installed.

To enable Agent Awareness, turn on the **DNS On-Prem Agent Awareness** toggle on any network.

<img src="https://mintcdn.com/goguardian/XFzHF494idV3Fqar/images/screenshots/dns-precision-filtering/step-04.png?fit=max&auto=format&n=XFzHF494idV3Fqar&q=85&s=6372091d92b3de0f57bf7fa169e55606" alt="Network toggle list showing the DNS On-Prem Agent Awareness toggle turned on" width="702" height="388" data-path="images/screenshots/dns-precision-filtering/step-04.png" />

## DNS Traffic Updates

[Browsing activity](https://admin.goguardian.com/activity) for a network with DNS Precision Filtering deployed is split across two tabs: **Agents** and **DNS**.

* The **Agents** tab shows activity from devices with a GoGuardian agent installed. These devices bypass DNS filtering when Agent Awareness is enabled.
* The **DNS** tab shows network-level activity for devices without an agent installed. Search by **Domain**, **Student**, or **IP Address**. Each result shows its category, filtering result, user, subnet, and network.

<img src="https://mintcdn.com/goguardian/XFzHF494idV3Fqar/images/screenshots/dns-precision-filtering/step-05.png?fit=max&auto=format&n=XFzHF494idV3Fqar&q=85&s=a50ff4296fade0565c508a218bba4f85" alt="DNS tab of browsing activity, showing the Domain, Student, and IP Address search dropdown and result columns" width="2492" height="1166" data-path="images/screenshots/dns-precision-filtering/step-05.png" />

<Note>
  DNS Precision Filtering also adds per-student reporting and per-student filtering to [GoGuardian DNS](/products/dns/understand-goguardian-dns), which is otherwise network-level only. Contact your GoGuardian Account Manager to learn whether DNS Precision Filtering is available for your deployment.
</Note>
