...
Table 8.8 Total Resource Usage for Different Use Cases
Intended Use Use | Total CPU | Total Virtual Memory GB (Without Software ADP) | Total Virtual Memory GB (With Software ADP) | Database Object Count | Grid Master Capable |
---|---|---|---|---|---|
Small Authoritative DNS | 4 | 8 | 10 | 100,000 | No |
Medium Authoritative DNS | 8 | 16 | 22 | 600,000 | Yes |
Large Authoritative DNS | 16 | 32 | 40 | 16,000,000 | Yes |
Recursive DNS (without acceleration) | 6 | 14 | 18 | 200,000 | Yes |
Large Recursive DNS (without acceleration) | 14 | 28 | 36 | 5,000,000 | Yes |
Small Grid Master | 10 | 18 | 26 | 1,000,000 | Yes |
Medium Grid Master | 12 | 22 | 30 | 2,000,000 | Yes |
Large Grid Master | 16 | 32 | 40 | 16,000,000 | Yes |
Small Recursive DNS (with acceleration) | 8 | 12 | NA | 100,000 | No |
Medium Recursive DNS (with acceleration) | 16 | 20 | NA | 100,000 | No |
Large Recursive DNS (with acceleration) | 26 | 30 | NA | 100,000 | No |
...
The table below lists the features that are either supported or not supported on the Software DNS cache acceleration platforms:
Table 8.9 Features on the Software DNS cache acceleration platforms
Features | Supported / Not Supported |
---|---|
Tiered licensing | Licensing is based on the Flex Grid Activation license on the Grid. Note that the queries per second are limited by the number of CPUs for IB-FLEX. |
RPZ | Yes, the maximum cache lifetime for DNS cache acceleration is set to 300 seconds if RPZ zones are configured for the member. |
Caching (A, AAAA, MX, CNAME, PTR) | Yes |
Do not cache: EDNS, TCP, Any, TSIG | Yes |
Caching over additional interfaces (v4, v6) | Yes |
Dump Acceleration Cache (CLI, GUI, PAPI) | Yes |
Clear Acceleration Cache (CLI, GUI, PAPI) | Yes |
Cache pre-fetch and cache refresh | Yes |
ACLs (Allow-queries/Responses, Match-Clients/Destination, Blackhole) | Yes |
AAAA Filtering (Bypassed but support configuring) | Yes |
Fixed RRSET ordering | Yes |
DNS64 | No |
DNS monitoring feature (netmon) | Yes, but unlike IB-4030 this feature captures DNS cached queries on the virtual DNS cache acceleration platform. |
DNS Query logging (BIND only) | Yes |
DNS Views | Yes, supports up to six DNS views. |
Forward/Stub zones | Yes |
Unbound as DNS resolver | Yes, unbound is supported through the Flex Grid Activation license. |
DNS cache acceleration related restrictions for configuration. | Yes, for NIOS version 8.2.0 restrictions are enforced based on whether the DNS cache acceleration feature is enabled or disabled. |
Reporting | Yes, please see Reports for IB-FLEX. |
VLAN | No, Infoblox does not support VLAN for virtual appliances. |
DSCP | No, Infoblox does not support DSCP for virtual appliances. |
Sort list | No |
Anycast (OSPF and BGP) | Yes |
BFD (Bidirectional Forwarding Detection) | Yes |
HA Support | Valid only for non-SRIOV. |
NIC Bonding | No |
Multiple-Interfaces on same subnet | No |
IP Rate-limit and Response logging | No |
EDNS Client Subnet support | No |
NXDOMAIN redirection | Yes |
DNSSEC (Bypassed but support configuring) | Yes |
Debug enhancements | Yes |
SNMP Support for DCA service related traps | Yes |
SNMP stats support for DNS QPS and CHR | Yes |
NX Mitigation | No |
NetFilter (Tracking tables) | No |
Traffic-capture (All modes) | Yes, partial support. Note that tcpdump captures both queries and responses. |
No flush-mode support for DNS cache acceleration cache | Yes |
Per-interface UDP DNS cache acceleration response counters | Yes |
CLI commands | You can use the commands |
DNS Query rewrite (Bypassed but supports configuring) | No |
Threat Protection | Supported on IB-FLEX platforms, but you cannot enable Software ADP and |
...
Table 9 Supported Reports for IB-FLEX
DNS Reports | Security (DNS) Reports | System Reports |
---|---|---|
DNS Query Rate by Query Type | DNS Top RPZ Hits | Flex Grid Licensing Features Enabled |
DNS Query Rate by Member | DNS Top RPZ Hits by Client | CPU Utilization Trend |
DNS Daily Query Rate by Member | DNS RPZ Hits Trend By Mitigation Action | Memory Utilization Trend |
DNS Daily Peak Hour Query Rate by Member | ||
DNS Replies Trend | ||
DNS Cache Hit Rate Trend | ||
DNS Top Requested Domain Names | ||
DNS Top NXDOMAIN / NOERROR (no data) | ||
DNS Top Clients | ||
DNS Top Timed-Out Recursive Queries | ||
DNS Response Latency Trend | ||
DNS Top SERVFAIL Errors Sent | ||
DNS Top SERVFAIL Errors Received | ||
DNS Object Count Trend for Flex Grid License | ||
DNS Effective Peak Usage Trend for Flex Grid License |