DNS setup best practice

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

DNS setup best practice

L3 Networker

Hi All ,

 

I am planning to use FQDN based address for security policy  . Any 

best practice to follow . As we have concern related to FQDN dns cache on firewall . And if we are connecting to cloud ( using hybrid setup)  any specific recommendation for that as well .

 

 

Thanks 

1 accepted solution

Accepted Solutions

@deepak12It will work.

For data plane request for https://abc.company.com/check/folder.. will get as https://<FQDN-IP-Address>/check/folder..

You only need to add object without https:// and any URI.

 

Mayur

M

View solution in original post

6 REPLIES 6

L3 Networker

@BPry   

 

HI  ,

 

Could you please give any suggestion here .

 

Thanks ..

Cyber Elite
Cyber Elite

@deepak12,

 

There are no as such best practice to follow. The only thing you need to consider is DNS configuration on the firewall. As when FQDN based object is configured on firewall, the MGMT plane sends DNS query requests to the configured DNS servers and populates all the IP addresses associated with configured FQDN object. These IP addresses are then forwarded to dataplane and act according to the security policy actions.

 

Here for Dataplane, this object only acts as a IP address but not as FQDN/domain. There is limit of max 10 IP addresses which are mapped by firewall to one FQDN object. There's no way to modify this limit. In this type of object, you cant configure wildcard domain. For wildcard domains, custom URL category it the option.

 

Hope it helps!

Mayur

M

@SutareMayur ,

Hi Mayur ,

 

Thanks for your help. My concern was mainly due to FQDN cache on firewalls. 

I have one more question.supoose we have fqdn along with Uri path like https://abc.company.com/check/folder..

For this case just using fqdn based address will work or need to go for custom url for this as well.

 

Thanks..

@deepak12It will work.

For data plane request for https://abc.company.com/check/folder.. will get as https://<FQDN-IP-Address>/check/folder..

You only need to add object without https:// and any URI.

 

Mayur

M

Hi @SutareMayur 

 

Thanks for your help ...

Cyber Elite
Cyber Elite

Hello All,

Also use a secure DNS provider as an added layer. https://www.youtube.com/watch?v=ROIAYSEbTuo

 

Regards,

 

 

 

Regards,

  • 1 accepted solution
  • 4299 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!