---
title: "Configuring Zone Transfers"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186336638/Configuring%20Zone%20Transfers"
format: markdown
---
<span style="color: #000000">To configure zone transfers, you identify the servers to which zone data is transferred and optionally, servers to which data must not be transferred. For example, you can allow transfers to a network, but not to a specific server in the network. You can specify a different set of servers for specific zones.  </span>

<span style="color: #000000">To configure zone transfer properties, complete the following:</span>

1. From the Infoblox Portal, click **Network** **>** <span style="color: #000000">**DNS**</span>, and click <span style="color: #000000">**Global DNS Configuration**</span>.
2. <span style="color: #000000">In the </span><span style="color: #000000">*Global DNS Configuration*</span><span style="color: #000000"> page, click </span><span style="color: #000000">**Zone Transfers**</span><span style="color: #000000">.</span>
3. <span style="color: #000000">In the </span><span style="color: #000000">**ACCEPT ZONE TRANSFER REQUESTS FROM**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Select one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Select this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Select this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Select this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Select this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers that have the </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  <span style="color: #000000">You can reorder the rows using the up and down arrows next to the table.</span>
4. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000"> to save.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Universal DDI supports incremental zone transfer. This feature is not user-configurable and is handled by Universal DDI automatically. Universal DDI will perform incremental zone transfers to decrease network load and to boost the speed of propagating the zone changes to NIOS-X Servers. This is useful for large zones, especially the ones that are changed frequently. In some cases, incremental zone transfers may not be performed due to certain factors or if secondary servers request a full zone transfer. In such cases, a full zone transfer will be performed.