Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

DNS over HTTPS (DoH) for web browsers provides online security by encrypting DNS queries, traditionally transmitted in plaintext. This encryption shields queries from interception and manipulation, mitigating risks associated with unauthorized surveillance or malicious activities. With DoH, each query is encapsulated within a secure tunnel, ensuring confidentiality and integrity as users navigate the internet. This technical advancement enhances the security posture of web browsers, safeguarding sensitive online interactions from potential threats.https://fc7ua07a-0g83-62fb-9feb-7684b14gv764.doh.threatdefense.infoblox.com/dns-query. This information can be obtained on

When traffic is sent over DoH, reports in the Infoblox Portal should show the source as "Unknown."

NOTE: To obtain your FQDN go to the General page of the Create New Security Policy wizard

...

in the Infoblox Portal(Infoblox Portal > Configure > Security. Copy the auto-generated FQDN, or click regenerate to generate a new FQDN. Note that DoH per Policy must be enabled in order to obtain the FQDN. The format should be https://FQDN/dns-query.

Sample FQDN. You can also view the information in the Privacy & Security options section of your web browser (see image 1).

Example from Mozilla Firefox.

Note that you can obtain the URL from your browser’s privacy and securty settings. Its location on Firefox is described in the following images (Settings > Privacy & Security). infoblox requires using increased or maximum protection settings:
https://fc7ua07a-0g83-62fb-9feb-7684b14gv764.doh.threatdefense.infoblox.com/dns-query.

Enabling DoH in Mozilla Firefox

To enable DoH to work with Mozilla firefox, perform the following:

  1. Select the menu button > Settings.

  2. In the Privacy & Security menu, scroll down to the Enable secure DNS using: section.

  3. Select Increased Protection or Max Protection.

  4. Select Custom add the custom FQDN, and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

Increased Protection: With increased protection, you can do the following:

...

Max Protection: With maximum protection, you can do the following:

  • Use a proivder provider of your choice

  • Warn if secure DNS is unavailable

    • Note: If secure SNS is unavailable, then web sites will not load nor function properly. If maximum protection is not possible, then it will fall back to increased protection.

Note that you can obtain the URL from your browser’s privacy and security settings. Its location in Firefox is described in the following image (Settings > Privacy & Security). Infoblox requires using increased or maximum protection settings.

...

Enabling DoH in Google Chrome

  1. Select the three-dot menu in your browser > Settings.

  2. Select Privacy and security > Security.

  3. Scroll down and enable Use secure DNS.

  4. Select the With option, and from the drop-down menu choose Infoblox Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

...

​​Enabling DoH in Microsoft Edge

  1. Select the three-dot menu in your browser > Settings.

  2. Select Privacy, Search, and Services, and scroll down to Security.

  3. Enable Use secure DNS.

  4. Select Choose a service provider.

  5. Select the Enter custom provider drop-down menu and select Infoblox Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

...

Enabling DoH in Brave

  1. Select the menu button in your browser > Settings.

  2. Select Privacy and security > Security.

  3. Under Advanced, enable Use secure DNS.

  4. From the Select DNS provider drop-down menu, choose Infoblox Threat Defense Select the With option, and from the drop-down menu choose Infoblox Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query..

...