Skip to content
Avanet

Configure Sophos DNS Protection filtering policies

A Filtering Policy determines which additional domains DNS Protection allows or blocks for selected locations or firewalls based on web categories and Domain Lists. Exactly one Filtering Policy can be assigned to each location. However, DNS Protection blocks domains with a poor threat score or dangerous reputation even without a custom policy and even when a Domain List allows them. Neither a custom policy nor its position in the overview can override this fundamental security decision.

The safe approach is therefore to inventory locations and requirements, assign a new policy only to a pilot location, choose categories conservatively, keep exceptions narrow, verify the results in Logs & Reports, and only then assign additional locations to the tested policy.

Distinguish between a Filtering Policy and an Endpoint policy

There are two different policy types under My Products > DNS Protection > Policies:

  • Filtering policies determine filtering decisions for assigned locations or firewalls.
  • Endpoint policies connect managed devices to a Secure DNS location through Sophos Endpoint. The associated Filtering Policy continues to make the actual allow or block decision.

A Filtering Policy therefore does not install an endpoint agent or assign computers. Configure Sophos DNS Protection for endpoints explains the device path. For the network path, by contrast, the firewall or internal resolver must send queries through a configured DNS Protection location.

Prerequisites and responsibilities

Before creating a policy, you need at least one previously configured location or firewall that is not yet assigned to another Filtering Policy. You should also define the required category baseline, necessary individual exceptions, and a small pilot group. The Filtering Policy controls only the allow or block decision; it does not replace the DNS path or the location or endpoint assignment.

A policy name such as DNS-Pilot-Office-Zurich can be chosen freely. It should clearly indicate its purpose and scope so that it is easy to identify in the overview, reports, and any subsequent rollback. Categories and Domain Lists, however, require a business owner who decides why an exception is necessary and when it will be reviewed again.

Plan before creating the policy

For each location, record at least the internet egress, affected networks, owner, business-critical domains, and desired review date. Multiple networks can use the same location and therefore the same Filtering Policy. If a guest network, server network, or pilot group requires different rules, it needs an appropriately separate location or endpoint assignment path.

Assignments are not a prioritized rule list: there is no first and second Filtering Policy for the same location. Because only one policy can be assigned, resolve conflicts through clear location boundaries, not the display order of the policies. The non-editable Default location can also be assigned to a policy.

For a low-risk pilot, create a new policy rather than changing the production policy directly. Existing locations then remain unchanged while a dedicated pilot location receives the new settings.

Create and assign a Filtering Policy

  1. Open My Products > DNS Protection > Policies > Filtering policies.
  2. Select Add Policy and enter a unique name, for example DNS-Pilot-Office-Zurich.
  3. Under Locations and firewalls, move the pilot location from Available to Assigned to this policy.
  4. Open Settings.
  5. Under Filtering by web category, first select a Built-in Filter Profile or use Let me specify.
  6. Optionally, under Filtering by domain lists, turn on Include domain lists when filtering and add the required lists.
  7. Set the required options under Safe search for search engines and YouTube.
  8. Scroll up and select Save.

Sophos supports a maximum of 50 Filtering Policies, but only one per location. If a required location cannot be assigned, first check under Filtering policies whether it is already listed for another policy. Document the intended assignment, remove the existing assignment in a controlled manner, and only then assign the location to the new policy.

Make deliberate category decisions

A Built-in Filter Profile shows Allow or Block for each Category Group and its categories. These values cannot be changed individually within the profile. For different requirements, select Let me specify:

  • Allow permits all categories in a Category Group.
  • Block blocks all categories in the group.
  • Specify expands the group so that each individual category can be set to Allow or Block.

Security categories should generally remain restrictive. For infrastructure categories such as Content Delivery, CRL, or OCSP, first check whether updates, certificate validation, or cloud services depend on them. Productivity, social media, and bandwidth categories are business decisions, not blanket malware controls. Do not block Uncategorized without a pilot because new legitimate services can temporarily appear there.

Opening an entire category to correct a single misclassification creates unnecessary access. A narrow Domain List is the better first measure in such a case. Check the complete URL in the SophosLabs Intelix portal and document the web category and threat score in the change. Consider a narrow temporary exception until the misclassification has been reviewed and corrected as described in the troubleshooting section.

Domain Lists and decision precedence

Category filtering controls entire web categories. Domain Lists provide targeted exceptions or additional blocks for specific domains. After Add list, select an existing list, apply it with Save, and set Allow or Block under Actions for each list. Manage Domain Lists in Sophos DNS Protection explains creation, syntax, and safe maintenance.

The effective decision is subject to these boundaries:

  1. A Domain List takes precedence over the normal category decision: Allow can exempt a domain from a blocked category, while Block can make an allowed category more restrictive.
  2. The security baseline remains in force above this. Domains that SophosLabs classifies as a Threat or Security Risk based on their threat score or reputation remain blocked even in an allow list.
  3. An allowed domain can still fail if its CNAME points to a target in a blocked category.

Limit exceptions to the domains actually required, document their purpose, owner, and review date, and do not maintain them as a catch-all list. Publicly resolvable internal company domains can be allowed if, for example, Parked Domains blocks them inappropriately. Private DNS zones, however, require the correct internal DNS or endpoint exclusion path; an allow list does not make them publicly resolvable.

Review Generative AI in existing policies

The Generative AI category belongs to the Business and generative AI Category Group. In existing Filtering Policies, it initially inherits the setting of the Information technology category. For example, if Information technology was set to Allow, Generative AI is also allowed. This is easy to overlook after a product update and should therefore be reviewed deliberately in every existing policy.

If only approved AI services should be accessible, block Generative AI in the Filtering Policy and exempt the approved domains through a narrowly scoped Domain List set to Allow. This list provides a clear record of the approved services without opening the entire category. Then test both an approved and an unapproved service using the pilot location that is actually assigned.

Configure Safe Search and YouTube

Enforce Safe Search for major search engines enforces Safe Search for Google, Yahoo, Bing, DuckDuckGo, and Yandex. Enforce YouTube restrictions offers Strict and Moderate; Moderate leaves a larger selection of videos available than Strict.

First test these options with the browsers, search engines, YouTube sign-in methods, and managed devices actually in use. They do not replace comprehensive web or application control. If a client uses a different DNS path, the Filtering Policy cannot operate reliably either.

Edit or delete an existing policy

To edit a policy, open My Products > DNS Protection > Policies > Filtering policies. The overview shows the policies that have been created and their assigned locations or firewalls. Select the required policy, change assignments or Settings, and save. Before changing a production category, record the previous state; ideally, take screenshots or create a brief change record containing the policy name, locations, profile, individual categories, Domain Lists, and Safe Search options.

Policy changes can be delayed by the DNS TTL of a domain that has already been resolved. A destination that remains accessible immediately after Save therefore does not automatically indicate an incorrect assignment. Resolve it again after the TTL expires, then check the reports.

To delete a policy, select it on the Filtering policies page and choose Delete. First document the assigned locations and the replacement path. Deleting the policy removes its custom category and Domain List controls; the fundamental block for domains with a poor threat score or dangerous reputation remains active.

Pilot, verify, and roll out

For the pilot, define an allowed business domain, a harmless domain deliberately blocked for testing, a narrow allow exception, and a narrow block exception. Also test critical update, certificate, sign-in, and cloud services. Do not choose a domain from a real malware list as the test domain.

Under DNS Protection > Logs & Reports, DNS usage by source is useful because the report shows queries by location and, for Sophos Endpoint, also by user and device. Filter by Location, Domain, Status, or Policy Action and check for the following signals:

  • The query appears under the expected location.
  • The effective action matches the category or Domain List.
  • An allow exception opens only the intended domain.
  • A block exception produces the expected block and, where applicable, the Sophos Block Page.
  • Critical services show no new concentration of blocked domains.

According to Sophos, reports are 15 to 25 minutes behind real time. Changed location or policy names can take 30 minutes to four hours to appear. Include this delay in the test plan; otherwise, a working policy may be changed prematurely.

After a successful pilot, assign only one additional clearly bounded location at a time to the tested policy, wait through an observation window, and only then continue. Use separate acceptance criteria for server, guest, and user networks.

Rollback

The fastest functional rollback is the documented previous state: remove the pilot location from the new policy and assign it back to the previous policy, or restore the changed Settings to their former values. Then save, account for DNS TTL and reporting delay, and repeat the same positive and negative tests.

Do not delete a Domain List during rollback. First remove it from the policy or return its Action to the documented previous state. A list that is still used by a policy cannot be deleted. This preserves traceability and allows the exception to be restored selectively after root-cause analysis.

Troubleshooting

An allowed domain remains blocked

First check the complete URL in the SophosLabs Intelix portal and record the web category and threat score. Then query the CNAME chain against the resolver actually in use with nslookup <domain-name> <dns-server-ip-address> on Windows or dig <domain-name> on Linux. Replace <domain-name> with the affected hostname and <dns-server-ip-address> with the DNS server address used by the client under test. Look for CNAME or Aliases in the response. Then check each returned CNAME target separately for its web category in the Intelix portal.

Only then compare the web category of each relevant CNAME target with the Category Action, and check the Domain List, list Action, and actual location assignment. If the category of a CNAME target or the original URL is demonstrably incorrect, submit that exact miscategorized target or URL for reclassification. Open Sophos Support and proceed as follows:

  1. Under Submit a Sample, select Web Address (URL).
  2. Enter the website under Web Address (URL).
  3. Under Product/Services, select Sophos XG Firewall. Sophos Firewall and DNS Protection use the same website categories.
  4. In Comments, state that the request concerns DNS Protection rather than Sophos Firewall, and add the business justification.
  5. Enter the contact details and select Submit URL.

Use a narrow temporary exception only if the security baseline permits it, and review it again after reclassification.

A block does not apply immediately after a change

Wait for the DNS TTL and resolve the name again on a pilot client. Then allow 15 to 25 minutes for the report data. Do not immediately add a broader block: first confirm that the client uses the intended DNS Protection path and the correct location.

A location receives the wrong policy

Under Filtering policies, check which policy lists the location. Because only one Filtering Policy can apply per location, there is no priority through which a second policy could override it. For endpoint devices, also verify which Endpoint policy connects the device to which Secure DNS location.

The Block Page or reports are missing

A DNS block returns the IP address of the Sophos Block Page server. If the visible page is missing, still check the policy event in the report first; certificate trust, reachability of blockpage.dnsprotection.sophos.com, and the actual DNS path are separate fault classes. If reports are also empty, wait for the reporting delay, then check the location, client resolver, and alternative DoH, VPN, or browser paths.