Using BloxOne as a DoH server

Using BloxOne as a DoH server

BloxOne Threat Defense offers the ability to utilize agent-less support for DNS resolution via DoH. In order to use BloxOne’s DoH feature, a security policy must be created to acquire a DoH URL. This URL can be leveraged by clients for direct DoH resolution of domains via BloxOne. The rules within the security policy the URL is acquired from will apply to traffic being resolved via the DoH URL. Additionally, any external networks added to the Security policy will be resolvable by clients using the DoH URL. For more information on external networks and security polices please view the Infoblox documentation portal.

This section covers how to acquire a DoH URL from a security policy in BloxOne.

Licensing and Certificate Requirements

To leverage BloxOne Threat Defense’s DoH feature a BloxOne Threat Defense Cloud or Advanced license is required.

Create a new security policy and acquire a DoH URL

To create a DoH URL from BloxOne the creation of a Security Policy is required. Alternatively, a DoH URL can be acquired from an existing security policy. For more information on how to acquire a DoH URL from an existing security policy please view the section here. Complete the following steps to acquire a DoH URL from BloxOne.

  1. Navigate to Policies → Security Policies.

  1. Click Create Security Policy.

  1. Give the new security policy a Name.

  1. (Optional) Give the new security policy a Description.

  1. Enable the toggle switch associated with DoH per Policy.

  1. Copy the URL that is visible and save it to a text editor for use later.



  1. Click Next.

  1. (Optional) Apply this security policy to any additional sources via the Add Source button if desired.

  1. Click Next.

  1. (Optional) Add any desired rules to this policy via the Add Rule button if desired.

  1. Click Finish.

  1. Click Save & Close to confirm the creation of the security policy.

  1. Add the DoH URL to any platform that supports DoH. For more information please refer to the documentation here.

Acquire a DoH URL from an existing security policy

A DoH URL can be acquired from an existing security policy. Complete the following steps to acquire a DoH URL from BloxOne.

  1. Navigate to Policies → Security Policies.

  1. Locate and click the hamburger icon associated with the existing security policy that the DoH URL is to be acquired from. Then, click Edit.

  1. Give the new security policy a Name.

  1. (Optional) Give the new security policy a Description.

  1. Enable the toggle switch associated with DoH per Policy.

  1. Copy the URL that is visible and save it to a text editor for use later.



  1. Click Finish.

  1. Click Save & Close to confirm the edits to the security policy.

  1. Add the DoH URL to any platform that supports DoH. For more information please refer to the documentation here.

Related content