Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

In DNS over HTTPS (DoH) for web browsers , you will need to use the following:
https://UNIQUE_LABEL.doh.threatdefense.infoblox.com/dns-query. This information can be obtained on provides online security by encrypting DNS queries, traditionally transmitted in plaintext. This encryption shields queries from interception and manipulation, mitigating risks associated with unauthorized surveillance or malicious activities. With DoH, each query is encapsulated within a secure tunnel, ensuring confidentiality and integrity as users navigate the internet. This technical advancement enhances the security posture of web browsers, safeguarding sensitive online interactions from potential threats.

When traffic is sent over DoH, reports in the Infoblox Portal should show the source as "Unknown."

NOTE: To obtain your FQDN go to the General page of the Create New Security Policy wizard

...

in the Infoblox Portal(Infoblox Portal > Configure > Security. Copy the auto-generated FQDN, or click regenerate to generate a new FQDN. Note that DoH per Policy must be enabled in order to obtain the FQDN.

...

The format should be https://FQDN/dns-query.

Sample FQDN:
https://fc7ua07a-0g83-62fb-9feb-7684b14gv764.doh.threatdefense.infoblox.com/dns-query.

Enabling DoH in Mozilla Firefox

To enable DoH to work with Mozilla firefox, perform the following:

  1. Select the menu button > Settings.

  2. In the Privacy & Security menu, scroll down to the Enable secure DNS using: section.

  3. Select Increased Protection or Max Protection.

  4. Select Custom add the custom FQDN, and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

Increased Protection: With increased protection, you can do the following:

  • Use the provider you select

  • Only use the defsault resolver if there is a problem with secure DNS.

Max Protection: With maximum protection, you can do the following:

  • Use a provider of your choice

  • Warn if secure DNS is unavailable

    • Note: If secure SNS is unavailable, then web sites will not load nor function properly. If maximum protection is not possible, then it will fall back to increased protection.

Note that you can obtain the URL from your browser’s privacy and securty security settings. Its location on in Firefox is described in the following images image (Settings > Privacy & Security). infoblox recommends Infoblox requires using increased and maximun protection settings.

(increased - fail open, max - fail closed)

...

or maximum protection settings.

...

Enabling DoH in Google Chrome

  1. Select the three-dot menu in your browser > Settings.

  2. Select Privacy and security > Security.

  3. Scroll down and enable Use secure DNS.

  4. Select the With option, and from the drop-down menu choose Infoblox Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

...

​​Enabling DoH in Microsoft Edge

  1. Select the three-dot menu in your browser > Settings.

  2. Select Privacy, Search, and Services, and scroll down to Security.

  3. Enable Use secure DNS.

  4. Select Choose a service provider.

  5. Select the Enter custom provider drop-down menu and select Infoblox Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

...

Enabling DoH in Brave

  1. Select the menu button in your browser > Settings.

  2. Select Privacy and security > Security.

  3. Under Advanced, enable Use secure DNS.

  4. From the Select DNS provider drop-down menu, choose Infoblox Threat Defense Select the With option, and from the drop-down menu choose Infoblox Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query..

...