---
title: "Creating DNS Views"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186401380/Creating%20DNS%20Views"
format: markdown
---
<span style="color: #000000">To create a DNS view, complete the following:</span>

1. <span style="color: #000000">From the Infoblox Portal, click </span>**Network**<span style="color: #000000"> > </span><span style="color: #000000">**DNS**</span><span style="color: #000000"> > </span><span style="color: #000000">**Zones**</span><span style="color: #000000">.</span>
2. <span style="color: #000000">Click </span><span style="color: #000000">**Create DNS View**</span><span style="color: #000000">.</span>
3. <span style="color: #000000">On the </span><span style="color: #000000">*Create DNS View*</span><span style="color: #000000"> page, specify the following:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter a name for the view.</span>
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Enter additional details about the view.</span>
  - <span style="color: #000000">**IP Space**</span><span style="color: #000000">: Select an IP space from the column selector. For more information, see</span><span style="color: #ff0000"> </span><span style="color: #ff0000">*[Configuring IP Space](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186369710)*</span><span style="color: #0000ff">*[s](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186369710)*</span><span style="color: #000000">. </span>
  - <span style="color: #000000">**Disable for DNS Protocol**</span><span style="color: #000000">: Select this check box to temporarily disable this view for DNS protocol.</span>
  - <span style="color: #000000">**Match recursive queries only**</span><span style="color: #000000">: Select this check box to match recursive queries. </span>
4. <span style="color: #000000">**Tags**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to associate keys with the view and specify the following details:</span>
  - <span style="color: #000000">**KEY**</span><span style="color: #000000">: Enter a meaningful name for the key, such as a location or a department.  </span>
  - <span style="color: #000000">**VALUE**</span><span style="color: #000000">: Enter a value for the key such as San Jose or Accounts.</span>
    <span style="color: #000000">To remove a tag, select the respective check box and click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to delete the associated tag. For information about tags, see </span><span style="color: #000000">*[Using Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186745865)*</span><span style="color: #000000">. </span>
5. <span style="color: #000000">In the </span><span style="color: #000000">**[Match Clients](#MatchClientsandMatchDestinations)**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs appear. If you have only one named ACL, the application automatically displays the named ACL. When you choose this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
6. <span style="color: #000000">In the </span><span style="color: #000000">**[Match Destinations](#MatchClientsandMatchDestinations)**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs appear. If you have only one named ACL, the application automatically displays the named ACL. When you choose this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
7. <span style="color: #000000">Select the </span><span style="color: #000000">**Use Minimal Responses**</span><span style="color: #000000"> check box to enable the return of minimal responses. Universal DDI returns a minimal amount of data in response to a query, by default. It includes the records in the authority and additional data sections of its response only when required, such as in negative responses. This feature speeds up DNS responses provided by the application.</span>
8. <span style="color: #000000">In the </span><span style="color: #000000">**ALLOW QUERIES FROM**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs appear. If you have only one named ACL, the application automatically displays the named ACL. When you choose this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
9. <span style="color: #000000">In the </span><span style="color: #000000">**DNS Sort Lists**</span><span style="color: #000000"> section, create </span><span style="color: #172b4d">DNS sort lists to prioritize A and AAAA records on certain networks when they are returned in DNS responses. For more information, see </span><span style="color: #172b4d">*[DNS Sort Lists](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/291865120)*</span><span style="color: #172b4d">*.*</span>
10. <span style="color: #000000">Extension Mechanism for DNS (EDNS) removes the limit of 512 bytes thereby avoiding fragmentation and packet loss for larger DNS messages sent over UDP. If the DNS messages sent over UDP are over 512 bytes, set an appropriate value to avoid DNS messages over UDP from getting fragmented. Configure the following: </span>
  - <span style="color: #000000">**Max Advertised UDP size**</span><span style="color: #000000">: Specify the UDP size in bytes. This is the size of a UDP message that the DNS server advertises to other DNS servers. The default size is 1232 bytes. The maximum UDP size allowed to be configured is 4096 bytes. The minimum UDP packet size allowed to be configured is 512 bytes.</span>
  - <span style="color: #000000">**Max UDP size sent**</span><span style="color: #000000">: Specify the UDP size in bytes. This is the maximum number of bytes the DNS server will send in a UDP response. The default size is 1232 bytes. The maximum UDP size allowed to be configured is 4096 bytes. The minimum UDP packet size allowed to be configured is 512 bytes.</span>
11. <span style="color: #000000">Configure </span><span style="color: #000000">**Zone Transfers**</span><span style="color: #000000">. For more information on Zone Transfers, see </span><span style="color: #000000">*[Configuring Zone Transfers](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186336638)*</span><span style="color: #000000">. </span>
12. <span style="color: #000000">Configure </span><span style="color: #000000">**Updates**</span><span style="color: #000000">. </span>
  - <span style="color: #000000">**Allow GSS-TSIG-signed updates**</span><span style="color: #000000">: Toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and select the check box to allow GSS-TSIG-signed updates. GSS-TSIG (Generic Security Service Algorithm for Secret Key Transaction) is used to authenticate DDNS updates. For more information, see </span><span style="color: #000000">*[Configuring GSS-TSIG](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186876219)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">For more information configuring dynamic updates, see </span><span style="color: #000000">*[Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186941553)*</span><span style="color: #000000">. </span>
13. <span style="color: #000000">Configure </span><span style="color: #000000">**Recursion**</span><span style="color: #000000">. For more information on Recursion, see </span><span style="color: #000000">*[Enabling Recursive Queries](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186779374)*</span><span style="color: #000000">. </span>
14. <span style="color: #000000">Configure </span><span style="color: #000000">**DNSSEC Validation**</span><span style="color: #000000">. For more information , see </span><span style="color: #000000">*[DNSSEC Validation](https://infoblox-docs.atlassian.net/wiki/pages/createpage.action?spaceKey=bloxoneddi&title=DNSSEC%20Validation&linkCreation=true&fromPageId=186401380)*</span><span style="color: #000000">. </span>
15. <span style="color: #000000">Configure </span><span style="color: #000000">**DNSSEC Signing**</span><span style="color: #000000">. For more information, </span><span style="color: #000000">*[DNSSEC Signing](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/1540620608)*</span><span style="color: #000000">.</span>
16. <span style="color: #000000">Configure </span><span style="color: #000000">**EDNS Client Subnet Configuration**</span><span style="color: #000000">. For more information on EDNS Client Subnet Configuration, see </span><span style="color: #000000">*[Enabling Recursive Resolution Using EDNS Client Subnet (ECS) Option](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186844311)*</span><span style="color: #000000">.</span>
17. <span style="color: #000000">Configure </span><span style="color: #000000">**Zone Settings Defaults**</span><span style="color: #000000">. For more information on Zone Settings Defaults, see </span><span style="color: #000000">*[Zone Settings Defaults](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186401490)*</span><span style="color: #000000">.</span>
18. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000">. </span>


> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Some values in the </span><span style="color: #000000">*Create DNS View*</span><span style="color: #000000"> page are inherited from the Global DNS Configuration. To override the values, slide the </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> toggle to </span><span style="color: #000000">**Override**</span><span style="color: #000000">. For additional information on inheritance, see </span><u><span style="color: #000000">*[DNS Inheritance](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/609320975)*</span></u><span style="color: #000000">.</span>


## > Macro (anchor)

Match Clients and Match Destinations 

The Match Clients may contain Named ACLs, which can include nested Named ACLs and negative entries (rules that deny specific address/network). When evaluating a Named ACL, if a client matches a negative entry within that ACL or any of its nested ACLs, such a negative match is treated as if no match occurred for that Named ACL. This behavior ensures consistent security by preventing unintended access through complex nested configurations. 

For example, if Match Clients contains a Named ACL 'acl1' that includes “deny IP address 10.10.10.10” entry, when client 10.10.10.10 is evaluated against 'acl1': 

1. 10.10.10.10 matches the negative entry in 'acl1'.
2. This negative match is considered 'no match'.
3. Named ACL 'acl1' is effectively bypassed for this client.
4. The subsequent entries in the Match Clients list will be checked against the client.

The same rules apply for Match Destinations.