Loading...
Loading...
Twingate Internet Security — DNS filtering, exit networks, browser security, and DNS-over-HTTPS. Load when the user mentions DNS filtering, content filtering, internet security, exit networks, egress routing, browser security, NextDNS, DoH, DNS categories, or profile priority. Also trigger on 'Internet Security', 'DNS Security Profile', 'fixed egress IP', or 'SaaS allowlisting' in a Twingate context. Also activate for DNS conflicts and symptom-shaped DNS queries: a third-party DNS filter or AV product conflicting with Twingate (Cisco Umbrella, DNSFilter, AdGuard, Avast Real Site Protection), CGNAT range conflicts (`100.96/12`), multiple-network-interface DNS resolution problems, "all nameservers have failed", DNS request delays on Linux, a Docker container's second DNS query returning the wrong IP, or a personal/DIY exit-network VPN built on Twingate.
npx skill4agent add twingate-solutions/twingate-assistant twingate-dns-securityreferences/dns-security-overview.mdreferences/dns-filtering.md100.96/12references/grep -ril "all nameservers have failed" references/ # -> 9539322912-twingate-linux-client-fails-to-start-logs-show-dns-errors.md
grep -ril "100.96/12" references/ # -> 4359531030-cgnat-ip-conflicts-...md
grep -ril "avast" references/ # -> 6928700605-dns-avast-real-site-protection.mdreferences/gh-*references/references/{slug}.mdtwingate.com/docs{numeric-id}-{slug}.mdgh-{org}-{repo}.md| If the user asks about… | Read first |
|---|---|
| DNS Security overview, profile design, exit-node config, DoH enforcement | |
| DNS filtering categories, allow/block lists, profile priority | |
| Internet Security product scope, licensing, client config | |
| Exit networks (egress IPs, configuration, AWS-specific patterns) | |
| Browser security features | |
| DNS over HTTPS (Cloudflare integration) | |
| NextDNS integration | |
| Cisco AnyConnect with Umbrella alongside Twingate | |
| Zscaler alongside Twingate | |
| Netskope DLP alongside Twingate | |
| Comprehensive DNS guide | |
| Personal/DIY exit-network VPN — Terraform deploys for Minikube, DigitalOcean Droplets, or DigitalOcean Kubernetes; requires Home/Enterprise plan (Exit Networks unavailable on Starter) | |
| Headless client on Ubiquiti UniFi gateways — systemd-nspawn container intercepting a VLAN's DNS via iptables + bind9 and forwarding through Twingate split-DNS resolvers, for whole-VLAN access with no per-device client | |
| Third-party DNS filter / AV conflicts — DNSFilter, AdGuard for Mac, Avast Real Site Protection running alongside Twingate | |
CGNAT range & multi-interface DNS conflicts — | |
| Linux DNS client bugs — client fails to start with "All nameservers have failed" (Network Manager v1.42+ incompatibility), general DNS request delays | |
macOS Docker DNS resolution bug — container's first DNS query succeeds, subsequent queries fall back to a non-CGNAT resolver; fix via pinning | |
references/