The following diagram illustrates BloxOne Universal DDI as the hidden primary master:
Drawio |
---|
mVer | 2 |
---|
zoom | 1 |
---|
simple | 0 |
---|
inComment | 0 |
---|
custContentId | 268995081 |
---|
pageId | 268535418 |
---|
lbox | 1 |
---|
diagramDisplayName | BloxOneDDI_Hidden_Primary_Master.drawio |
---|
contentVer | 23 |
---|
revision | 23 |
---|
baseUrl | https://infoblox-docs.atlassian.net/wiki |
---|
diagramName | BloxOneDDI_Hidden_Primary_Master.drawio |
---|
pCenter | 0 |
---|
width | 870.5 |
---|
links | |
---|
tbstyle | |
---|
height | 611 |
---|
|
Image Modified |
BloxOne Universal DDI is the Primary Master |
BloxOne CSP BloxOne DNS servers on prem and on-prem BloxOne DNS serverNIOS-X Physical Server. A third party
|
hosted DNS servers hosting serving the target zone. DNS servers in different locations on different platforms provide for maximum redundancy and availability. Inbound port 53 requests are blocked. Attempts are made because NS records exist for
|
BloxOne DNS servers |
Image Modified |
BloxOne DNS NIOS-X Server | In the DMZ with access to the server only from the NIOS DNS server in the public cloud and the other NIOS DNS servers in the DMZ. Allows zone transfers using a TSIG key. Port 53 only available on the
|
host |
Image Modified NIOS DNS Servers |
NIOS Universal DDI DNS servers in the DMZ allow zone transfers from the 3rd party DNS provider via TSIG key. Port 53 accessible through the firewall (to NIOS DNS only). Public Cloud NIOS DNS requires secure connection to DMZ to pull a zone transfer. Optionally configured with vADP to provide additional protection of DNS services. NS (and possibly A) resource records must be created for each NIOS secondary.
|
Image Modified Third Party DNS Servers | Provide DNS services as a redundancy and availability service. Reduces risk of DDoS and network outages to on-prem DNS servers. Provides additional scalability. NS resource records must be created for appropriate systems. NIOS DNS Servers Offer GSLB Responses. NIOS DNS servers licensed for DTC may provide rule-based responses for inbound queries.
|