Configuring DNS Tunnel Detection
To configure DNS tunnel detection
Â
- Navigate to POLICY | DNS Security | Settings.
- Click the DNS Tunnel Detection tab.
- Under Settings, select Enable DNS Tunnel Detection to enable DNS tunnel detection.
- To block all the DNS traffic from the detected clients, select Block All The Clients DNS Traffic.
- Click Accept.

Â
 Detected Suspicious Client Information
 SonicOS displays information about all hosts that have established a DNS tunnel in the Detected Suspicious Clients Info table.
 To view detected suspicious client Information
Â
- Navigate to POLICY | DNS Security | Settings.
- Hover over to the DNS Tunnel Detection tab.
- Click on the Detected Suspicious Clients Info tab

 This table is populated only if DNS tunnel detection is enabled. Hosts are dropped only if blocking clients' DNS traffic is enabled.Â
 Â

Creating White list for DNS Tunnel Detection
You can create white lists for IP address you consider safe. If a detected DNS tunnel IP address matches an address in the white list, DNS tunnel detection is bypassed.
Â
To create a DNS white list
Â
- Navigate to POLICY | DNS Security | Settings.
- Hover over to the DNS Tunnel Detection tab.
- Click on the White List for DNS Tunnel Detection tab.
- For each IP address, you want to add to the white list:
Click +Add. The Add One White Entry dialog displays.
In the IP Address field, enter the IP address of the domain to be added to the whitelist.
Click Save.

Deleting White List Entries for DNS Tunnel Detection
To delete all white list entries for DNS tunnel detection
Â
- Navigate to POLICY | DNS Security | Settings.
- Hover over to the DNS Tunnel Detection tab.
- Click on the White List for DNS Tunnel Detection tab.
- Select an entry to delete or select the top checkbox next to the IP Address column to select all of the items.
- Click Delete.
To delete white list entry, click on the entry and click on DELETE.