Document toolboxDocument toolbox

Amazon Route 53 Integration

Amazon Route 53 is a cloud DNS web service that routes end users’ requests to internet applications and resources by resolving domain names into IP addresses and IP addresses into domain names. In Amazon Route 53, DNS records are organized into hosted zones, which are configured through the Route 53 API, AWS CLI, or AWS Management Console.

Universal DDI provides the capability for synchronizing and integrating public-hosted zones with Amazon Route 53, and this allows users to view and manage Route 53 DNS data through the Infoblox Portal. Also, NIOS-X Servers can be configured to service zones synchronized from Route 53. For more information about Amazon Route 53, refer to the Amazon Route 53 documentation.

The Infoblox Amazon Route 53 integration feature offers the following:

  • Two-way synchronization of public NIOS-X Server zones and records from AWS Route 53 to Universal DDI. Synchronization of AWS resource records configured with a simple routing policy is supported. Other routing policies are not supported. Synchronization of DNSSEC records is not supported.

  • Private zones can be updated or deleted. Infoblox Portal does not support Create operation for private zones.

  • Create, Update, and Delete operations are supported for resource records.

  • Viewing and management of AWS-hosted zones and records through the Infoblox Infoblox Portal. For more information, see Limitations of AWS Route 53 Integration.

  • A Universal DDI NIOS-X Server can directly respond to DNS queries from clients for private zones that are managed in AWS Route 53. A Universal DDI NIOS-X Server can be configured as a secondary DNS server for local clients thereby reducing the network load since the queries do not need to recurse to AWS Route 53. 

The following diagram illustrates how to leverage the Route 53 integration feature. In an architecture that consists of on-premise networks and an AWS public cloud, NIOS-X Servers can be configured to service zones that have been synchronized from Route 53. DNS data synchronized from Amazon Route 53 is transferred from the Infoblox Portal to NIOS-X Servers. DNS clients in the enterprise data center can then send queries for Route 53–integrated zones to the NIOS-X Servers. 

To integrate AWS Route 53 with Universal DDI, complete the following steps:

  1. Go to Configure > Administration > Credentials, and configure Amazon Route 53 credentials. For more information, see Creating AWS Route 53 Credentials.

  2. Go to Configure > Networking > Discovery > Cloud, and configure AWS Route 53. For more information, see Configuring Network Discovery.

  3. Go to Configure > Networking > DNS > Zones > Edit Zone, and add an NIOS-X Server to AWS-synced zones. This step is optional. You can add a NIOS-X Server to a primary zone or a secondary zone. You can edit the primary zone or secondary zone and add the NIOS-X Server as an Authoritative DNS Server or add the NIOS-X Server to a DNS Server Group, and add the group to the primary zone or secondary zone. For more information, see Creating a Primary Zone or Creating a Secondary Zone.

All Route 53 private zones are associated with a VPC in AWS.  Each VPC represents a private network.  It is quite possible that within one AWS tenant there are overlapping networks and zones between VPC. Therefore, to avoid conflict errors in Universal DDI, a new DNS view will be created for each VPC grouping that is synced. Zones with each VPC grouping will be added within the DNS view that has been created for each respectively. It is expected that in most cases, the VPC grouping will consist of a single VPC.  However, for the cases where a zone is assigned to multiple VPC's, the grouping would include all VPC's assigned to the zone.  In this latter case, the vpc-view represents all VPCs in the grouping.

 

You can perform the following actions:

Â