Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 18 Current »

DNS over HTTPS (DoH) for web browsers provides online security by encrypting DNS queries, traditionally transmitted in plaintext. This encryption shields queries from interception and manipulation, mitigating risks associated with unauthorized surveillance or malicious activities. With DoH, each query is encapsulated within a secure tunnel, ensuring confidentiality and integrity as users navigate the internet. This technical advancement enhances the security posture of web browsers, safeguarding sensitive online interactions from potential threats.

When traffic is sent over DoH, reports in the Cloud Services Portal should show the source as "Unknown."

NOTE: To obtain your FQDN go to the General page of the Create New Security Policy wizard in the Cloud Services Portal (Cloud Services Portal > Policies > Security Policies > Create New Security Policy > General). Copy the auto-generated FQDN, or click regenerate to generate a new FQDN. Note that DoH per Policy must be enabled in order to obtain the FQDN. The format should be https://FQDN/dns-query.

Sample FQDN:
https://fc7ua07a-0g83-62fb-9feb-7684b14gv764.doh.threatdefense.infoblox.com/dns-query.

Enabling DoH in Mozilla Firefox

To enable DoH to work with Mozilla firefox, perform the following:

  1. Select the menu button > Settings.

  2. In the Privacy & Security menu, scroll down to the Enable secure DNS using: section.

  3. Select Increased Protection or Max Protection.

  4. Select Custom add the custom FQDN, and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

Increased Protection: With increased protection, you can do the following:

  • Use the provider you select

  • Only use the defsault resolver if there is a problem with secure DNS.

Max Protection: With maximum protection, you can do the following:

  • Use a provider of your choice

  • Warn if secure DNS is unavailable

    • Note: If secure SNS is unavailable, then web sites will not load nor function properly. If maximum protection is not possible, then it will fall back to increased protection.

Note that you can obtain the URL from your browser’s privacy and security settings. Its location in Firefox is described in the following image (Settings > Privacy & Security). Infoblox requires using increased or maximum protection settings.

Setting up DoH profile for use with mozilla Firefox browser.

Enabling DoH in Google Chrome

  1. Select the three-dot menu in your browser > Settings.

  2. Select Privacy and security > Security.

  3. Scroll down and enable Use secure DNS.

  4. Select the With option, and from the drop-down menu choose BloxOne Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

Setting up DoH profile for use with Google Chrome browser

​​Enabling DoH in Microsoft Edge

  1. Select the three-dot menu in your browser > Settings.

  2. Select Privacy, Search, and Services, and scroll down to Security.

  3. Enable Use secure DNS.

  4. Select Choose a service provider.

  5. Select the Enter custom provider drop-down menu and select BloxOne Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query.

Setting up DoH profile for use with Microsoft Edge browser

Enabling DoH in Brave

  1. Select the menu button in your browser > Settings.

  2. Select Privacy and security > Security.

  3. Under Advanced, enable Use secure DNS.

  4. From the Select DNS provider drop-down menu, choose BloxOne Threat Defense Select the With option, and from the drop-down menu choose BloxOne Threat Defense and add the custom FQDN that is generated under security policy when DoH is enabled. The format should be https://FQDN/dns-query..

Setting up DoH profile for use with Brave browser.


  • No labels