SonicOS 7.1 DNS Guide
- SonicOS 7.1
- About SonicOS
- About Network
- Configuring DNS Settings
- Configuring Dynamic DNS
- Configuring DNS Proxy Settings
- SonicWall Support
About DNS Proxy
An IPv4 interface can do name resolution on an IPv4 Internet, and an IPv6 interface can only do name resolution on an IPv6 Internet through DNS proxy. To allow IPv4 clients to access DNS services in a network with mixed IPv4 and IPv6 interfaces,SonicOS supports DNS proxy.
The DNS proxy feature provides a transparent mechanism that allows devices to proxy hostname resolution requests on behalf of clients. The proxy can use existing DNS cache, which is either statically configured by you or learned dynamically, to respond to the queries directly.
The proxy can redirect the DNS queries selectively to specific DNS servers, according to partial or complete domain specifications. This is useful when VPN tunnels or PPPoE virtual links provide multiple network connectivity, and it is necessary to direct some DNS queries to one network, and other queries to another network.
With DNS Proxy, LAN Subnet devices use the SonicWall network security appliance as the DNS Server and send DNS queries to the network security appliance. The network security appliance proxies the DNS queries to the real DNS Server. In this way, the network security appliance is the central management point for the network DNS traffic, providing the ability to manage the DNS queries of the network at a single point.
To maintain security, an incoming DNS Query is proxied only after Access Rule and DPI checking.
About the access rule, behavior depends on the device mode:
On global mode devices:
Access rules will be auto-added according to the DNS rule configurations.
On policy mode devices:
Access rules need to be manually added after enabling DNS rules. Navigate to POLICY | Rules and Policies> DNS Rules page to enable DNS rules. For more information about DNS Rules, refer to Rules and Policies guide.
- Supported Interfaces
- DNS Server Liveness Detection and Failover
- DNS Cache
- High Availability Stateful Synchronization of DNS Cache
Was This Article Helpful?
Help us to improve our support portal