Document toolboxDocument toolbox

Using DNS Fallback

infoblox provides DNS fallback mechanisms to ensure DNS protection for your networks in cases where your local DNS resolver is temporarily offline or when the connection from your  hosts to Infoblox Platform is unavailable. When you enable DNS fallback, your system will always have a functional name server to fall back to, so your DNS queries can always be resolved.

Depending on your network setup, you can enable DNS fallback when you configure DFP (DNS Forwarding Proxy) settings via the Infoblox Portal or setting up DFP on NIOS.

DFP Settings via the Infoblox Portal

To enable DNS fallback on a DFP service in the Infoblox Portal:

  1. Log in to the Infoblox Portal.
  2. Go to Configuration > Infrastructure > Services.
  3. Select the DFP service on which you want to configure DNS fallback, and then click Edit.
  4. Click the DNS Forwarding Proxy tab and expand the Internal and Fallback Local Resolvers section.
  5. Click Add and add to the table the FQDN or IP address of the fallback DNS server.
  6. Enable the Fallback Resolver option for the fallback address.
  7. Click Next.
  8. Click Save & Close.

For information about DFP fallback to local DNS server and health checks, see DNS Forwarding Proxy Fallback to Local DNS Server.

DFP on NIOS Settings via the Grid Manager

To configure DNS fallback using DFP on NIOS:

  1. Log in to the NIOS Grid Manager UI.
  2. Select a Grid member and navigate to Grid Member > DFP Properties.
  3. Select the Fallback to the default resolution process if Infoblox Threat Defense does not respond check box.

When you select the check box, the DNS queries will fall back to the root server(s) even if there are forwarders added at the DNS member level. If you cannot enable the root servers or if the root servers are not reachable, ensure that you use DNS protection by enabling Fallback Resolver when configuring the applicable DFP service, so the DNS queries will fall back to the configured server(s). For information, see Configuring DNS Forwarding Proxy Settings.