Skip to content
Avanet

Understand and validate the Sophos DNS Protection dashboard

The Sophos DNS Protection dashboard combines a setup check with a compact operational overview. Open it in Sophos Fusion (formerly Sophos Central) at My Products > DNS Protection > Dashboard. It shows the Setup Assistant, Usage summary, the DNS Protection traffic history, and Top domains (last seven days). For an introduction to the service, licensing, and basic setup, see Sophos DNS Protection—free with Xstream Protection.

Dashboard data is approximately 15 to 25 minutes behind real time, so a new test query may not appear immediately. Use the dashboard for trends and setup progress; use View all and Logs & Reports to investigate individual queries.

Use the Setup Assistant correctly

Set up DNS Protection guides the initial configuration, but it is not a complete functional test:

  1. Add locations opens My Products > DNS Protection > Locations. A Default location already exists; the assistant then shows the number of configured locations.
  2. Set up your network opens Installers. Copy the DNS Protection IP addresses and, if required, download the Root Certificate. Then configure the network, resolver, or devices.
  3. On return, Queries shows how many locations have sent queries. This metric covers active locations from the last three months, so recently deleted entries may still be counted.
  4. In Add policy, Create policy opens My Products > DNS Protection > Policies; on return, the assistant shows the policy count.
  5. Review logs opens My Products > DNS Protection > Logs & Reports, where you verify location, source, and policy.
  6. Deploy to devices opens My Products > DNS Protection > Policies > Endpoint policies. This step is for Sophos Endpoint; a network-only deployment does not require an Endpoint policy.
  7. When Sophos detects completion, it displays Congratulations! Set up appears to be complete.

Use Hide to dismiss the assistant and Set up DNS Protection to display it again. Hiding it does not change any configuration.

Avanet recommendation: Do not treat the success message as acceptance. Confirm permitted and controlled blocked queries from every relevant location in Logs & Reports after the processing delay.

Interpret Usage summary

Selecting a Usage summary counter opens its report for the last 24 hours:

  • Total DNS queries: all resolved queries from all locations, whether permitted or blocked. A high value alone is not a security finding.
  • Security threats blocked: queries blocked for security reasons. Investigate their sources and recurrence promptly.
  • Policy violations blocked: queries blocked by your policies; Security blocks are excluded. An increase may be intentional or may indicate an incorrect policy assignment.
  • Active computers: computers active during the last 24 hours; shown only with Sophos Endpoint.
  • Active locations: locations from which at least one query was received. This does not prove continuous availability.

Do not compare these counters as if they should match. A meaningful warning sign is unexpected query volume combined with missing expected locations. Verify it in detailed reports filtered by location. Blocks without expected test traffic require a review of the source, domain, and policy.

Read DNS Protection traffic

The DNS Protection traffic graph shows DNS query volume, meaning the number of queries over 3 hours, 24 hours, or 30 days. It provides comparisons with Last week or Last month (4 weeks ago). The 24 hours and 30 days views also show the previous month’s daily average.

  • A drop may reflect a quiet period, a site outage, changed DNS forwarding, or an incorrect location assignment.
  • A spike may result from updates, cloud services, a new site, or faulty clients.
  • A stable total does not rule out the loss of one location.

The graph is not an availability monitor. Select View all and narrow anomalies by time and location in the detailed reports.

Assess Top domains (last seven days) and protected computers

Top domain queries covers seven days and separates Permitted domains, Security blocks, and Policy blocks. A frequent domain is not automatically suspicious: operating systems, CDNs, security products, and SaaS applications can generate many queries. Assess its category, business purpose, source, and timing. Trace repeated Security blocks to the originating device; numerous Policy blocks may show either an effective rule or an unnecessary software retry loop.

With Sophos Endpoint, DNS usage from protected computers lists the top seven protected computers with Username, Device name or ID, and permitted or blocked queries. View all uses DNS usage by source for Permitted domains and Policy blocks, and High risk devices for Security blocks. This is a prioritization list, not a complete inventory.

Validate the setup safely

Never use a real malicious domain or a broadly assigned production policy for a block test:

  1. Record the test location’s current policy assignment.
  2. Use a dedicated, tightly scoped test location or pilot group. Assign a temporary test policy containing exactly one harmless domain in a block domain list. Do not block an entire category for production users.
  3. From that same scope, query one known permitted domain and the harmless test domain.
  4. Wait at least 25 minutes. In Logs & Reports, verify the location, source, policy, and decision for both queries.
  5. Check that Total DNS queries, the relevant block counter, and Active locations respond plausibly. With Sophos Endpoint, also check the computer report.
  6. Remove the test entry and restore the recorded policy assignment. Repeat the permitted query and confirm it in Logs & Reports.

Only the combination of a permitted and blocked query validates transport and policy enforcement. A successful page load alone does not prove that the query passed through DNS Protection.

Understand delays and apparent discrepancies

Dashboard areas use different windows: counter links use 24 hours, Top domain queries and the computer report use seven days, and the Setup Assistant may cover three months. Values therefore need not match. A deleted location may remain in the assistant; Active computers is absent without Sophos Endpoint; a domain may remain in a seven-day ranking without activity today. Policy violations blocked and Security threats blocked are distinct block types.

For an incident time window, rely on Logs & Reports; use the dashboard for orientation.

Troubleshoot by symptom

The assistant does not complete

Open each step through the assistant and return to Dashboard. Confirm that at least one location sends traffic, a policy exists, and Logs & Reports contains queries. In a network-only design, Deploy to devices may intentionally remain unused; functional validation matters more than a complete checklist.

No or too few queries appear

Wait 25 minutes after a test. Then check the configured resolvers, DNS bypass paths, the public source IP or Secure DNS assignment, and the location filter in Logs & Reports. If the detailed report is also empty, the fault is upstream of the dashboard—typically DNS forwarding, device deployment, reachability, or location assignment.

Block counters or top domains look wrong

Compare the same period, then inspect the domain, block reason, source, and applied policy in the detailed report. Seven-day rankings react more slowly than a 24-hour report.

Active locations is higher than expected

The Setup Assistant includes activity from the last three months and may retain recently deleted entries. Use Locations for current inventory and time-filtered reports for current activity.

Active computers or the computer report is missing

These areas require Sophos Endpoint. Their absence is expected in a network-, firewall-, or resolver-only deployment.

Turn the dashboard into operational decisions

Daily checks should cover unexpected Security threats blocked, substantial volume drops, and missing expected locations. Weekly, compare Last week, assess recurring top domains, and confirm that Policy blocks still reflect the intended rules. Before allowing or blocking a domain, review the detailed report, affected sources, business purpose, and policy scope; test changes narrowly and validate again.