Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

Overview

When you manage a NETGEAR Pro Router using NETGEAR Insight and Exium DNS Security is enabled, legitimate domains might be blocked if they are classified as malicious, dynamic DNS, or low reputation. In these cases, DNS requests are redirected to an internal sinkhole IP address (172.18.x.x) instead of the domain’s actual public IP.

This can impact services such as DDNS, external IP detection, NTP, firmware updates, or third-party integrations.

Check if a domain is blocked

  1. Log in to Insight at insight.netgear.com
  2. Click the Devices tab, and select the Pro Router.
  3. Click Troubleshoot → DNS Lookup.
  4. Enter the Domain Name or IP Address for which you want to perform the DNS lookup.
  5. Click the Test Now button.

If the result shows an IP address in the 172.18.x.x range (e.g., 172.18.16.200), the domain is being sinkholed by DNS security. If the result shows a normal public IP address, DNS security is not the cause. Investigate other potential issues.

Before You Allow a Domain

Only allow a domain if you trust it and it is required for your setup. If you allowlist a domain, it bypasses DNS Security.

Before you allowlist a domain, consider the following questions:

  • What service or feature requires this domain? 
  • Did the service work before DNS security was enabled? 
  • Is this a domain you registered or manage (e.g., a custom DDNS domain)? 

Allow a trusted domain

  1. Navigate to the MSP admin console, and navigate to Client Workspace.
  2. Click Sites → Local Policies → Local Web Filter.
  3. From the Select Gateway option, ensure that your gateway is selected.
  4. Click the Add Policy button to create a new policy.
  5. In the Name field, add the name of the policy.
  6. In the Action section, click Allow.
  7. From the Source Type menu, select an option (click Select All for all LAN subnets).
  8. In the Content Types section, select Applications or Custom Domains.
  9. In the Domain field, enter a domain to allow.
  10. Click the Save button.

Verify

  • Run another DNS lookup in the device UI to confirm it resolves to a public IP (not 172.18.x.x)
  • Test the affected service (DDNS update, firmware check, NTP sync, etc.) to confirm it is working. 

If the domain still remains blocked after you add it to the allowlist, contact the Netgear support team.

For more information, see the router user manual at netgear.com/support/ and the following articles in the Exium Academy:

Last Updated:04/29/2026 | Article ID: 000070693

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email