---
title: "Creating DNS Config Profiles"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186681371/Creating%20DNS%20Config%20Profiles"
format: markdown
---
> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">The values for the DNS Config profiles are inherited from the Global DNS Configuration. To override the values, slide the </span>**Inherit**<span style="color: #000000"> toggle to </span>**Override**<span style="color: #000000">. For additional information on inheritance, see </span><span style="color: #0000ff">*[DNS Inheritance](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/609320975)*</span><span style="color: #000000">.</span>

<span style="color: #000000">To configure a DNS config profile, complete the following:</span>

1. From the Infoblox Portal, click **Network** > <span style="color: #000000">**DNS**</span> > <span style="color: #000000">**DNS Config Profiles **</span>> <span style="color: #000000">**Create DNS Config Profile.**</span>
2. <span style="color: #000000">On the </span><span style="color: #000000">*Create DNS Config Profiles *</span><span style="color: #000000">page, specify the following:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter a name for the DNS config profile</span><span style="color: #000000">**.**</span>
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Enter additional details about the DNS config profile.</span>
3. <span style="color: #000000">**Tags**</span><span style="color: #000000">: For information about tags, see </span><span style="color: #0000ff">*[Managing Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186745865)*</span><span style="color: #000000">.</span>
4. <span style="color: #000000">In the </span><span style="color: #000000">**ALLOW QUERIES FROM**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Select one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Select this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Select this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Select this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Select this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you only have one named ACL, the application automatically displays the named ACL. When you select this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">.</span>
5. <span style="color: #000000">In the </span><span style="color: #000000">**AAAA FILTERING**</span><span style="color: #000000"> section, configure the following:</span>
  - <span style="color: #000000">**Filtering**</span><span style="color: #000000">: Choose one of the following options for filtering AAAA records:</span>
  - <span style="color: #000000">**Enabled**</span><span style="color: #000000">: Choose this option of you want to enable AAAA filtering.</span>
  - <span style="color: #000000">**Disabled**</span><span style="color: #000000">: Choose this option if you want to disable AAAA filtering. </span>
  - <span style="color: #000000">**Break DNSSEC**</span><span style="color: #000000">: Enabling </span><span style="color: #000000">**Break DNSSEC**</span><span style="color: #000000"> for AAAA filtering means that AAAA records are removed from DNS responses, even if they are DNSSEC-signed, which can cause DNSSEC validation to fail.</span>
6. <span style="color: #000000">In the </span><span style="color: #000000">**REMOVE AAAA RECORDS IN RESPONSE TO**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Select one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Select this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Select this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Select this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv6 Address**</span><span style="color: #000000">: Select this option to add an IPv6 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv6 Network**</span><span style="color: #000000">: Select this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv6 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Select this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you only have one named ACL, the application automatically displays the named ACL. When you select this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">.</span>
7. <span style="color: #000000">In the </span><span style="color: #000000">**FAULT TOLERANT CACHING**</span><span style="color: #000000"> section, configure the following settings:</span>
  - <span style="color: #000000">**Enable Fault Tolerant Caching**</span><span style="color: #000000">: Select the check box to enable the DNS Server (NIOS-X Server or NIOS-X as a Service) to respond to DNS queries when the server is down. When you enable this option, the DNS server (NIOS-X Server or NIOS-X as a Service) retains the expired records in the recursive cache. Whenever recursive queries times out or returns a SERVFAIL response, the NIOS-X Server or NIOS-X as a Service returns the cached response to the client instead of the SERVFAIL response. This option is disabled by default.</span>When you enable <span style="color: #172b4d">DNS fault tolerant cache, you can also specify the TTL (time-to-live) and timeout settings for the expired records. TTL specifies the time duration for which the expired record is retained in the recursive cache. Setting a high TTL might cause the client to use incorrect data for a longer duration. Conversely, setting a low TTL renders more current cached data, but also increases the traffic on your network. The expired record is deleted from the recursive cache after the specified timeout duration.  For more information, see </span><span style="color: #172b4d">*[Best Practices for Fault Tolerant Caching](http://infoblox-docs.atlassian.net/wiki/spaces/ddiadminguidensdraft/pages/1396342900)*</span><span style="color: #172b4d">. </span>
    - <span style="color: #000000">**Expired Record TTL**</span><span style="color: #000000">: Specify the time duration that the DNS server must serve the expired records from the recursive cache before attempting to refresh the records. The default is five seconds. Select the time period in minutes, hours, or days from the drop-down list.</span>
    - <span style="color: #000000">**Expired Record Timeout**</span><span style="color: #000000">: Specify the time duration that the DNS server waits before deleting the expired records from recursive cache. The default is 24 hours. Select the time period in minutes, hours, or days from the drop-down list.</span>
8. <span style="color: #000000">In the </span><span style="color: #000000">**ACCEPT ZONE TRANSFER REQUESTS FROM**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Select one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Select this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Select this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Select this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Select this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers that have the </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">.</span>
9. <span style="color: #000000">In the </span><span style="color: #000000">**DNS Sort Lists**</span><span style="color: #000000"> section, create </span><span style="color: #172b4d">DNS sort lists to prioritize A and AAAA records on certain networks when they are returned in DNS responses. For more information, see </span><span style="color: #172b4d">*[DNS Sort Lists](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/291865120)*</span><span style="color: #172b4d">*.*</span>
10. <span style="color: #000000">In the </span><span style="color: #000000">**ALLOW DYNAMIC UPDATES FROM**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Select one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Select this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Select this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Select this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Select this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers that have the </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">.</span>
11. <span style="color: #000000">In the </span><span style="color: #000000">**Recursion**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> </span><span style="color: #000000">**recursion**</span><span style="color: #000000"> to enable recursion, and specify the following:</span>
  - <span style="color: #000000">**Allow GSS-TSIG–signed updates**</span><span style="color: #000000">: To allow GSS-TSIG–signed updates, select this checkbox. GSS-TSIG (Generic Security Service Algorithm for Secret Key Transaction) is used to authenticate DDNS updates. For more information, see </span><span style="color: #000000">*[Configuring GSS-TSIG](https://docs.infoblox.com/display/ddiadminguidensdraft/Configuring+GSS-TSIG)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">In the </span><span style="color: #000000">**GSS-TSIG CONFIGURATION**</span><span style="color: #000000"> section, choose one of the following options:</span>
    - <span style="color: #000000">**New GSS-TSIG Keytab File**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Select File**</span><span style="color: #000000">, find the keytab file, and click </span><span style="color: #000000">**Add**</span><span style="color: #000000">.</span>
    - <span style="color: #000000">**Existing GSS-TSIG Keytab File**</span><span style="color: #000000">: Select the keytab file from the drop-down, and click </span><span style="color: #000000">**Add**</span><span style="color: #000000">. The following read-only information is shown:</span>
      - <span style="color: #000000">**PRINCIPAL**</span><span style="color: #000000">: The principal name that is mapped to the keytab file</span>
      - <span style="color: #000000">**DOMAIN**</span><span style="color: #000000">: The name of the domain that is mapped to the keytab file</span>
      - <span style="color: #000000">**VERSION**</span><span style="color: #000000">: The version of the keytab file</span>
      - <span style="color: #000000">**ENCRYPTION TYPE**</span><span style="color: #000000">: The encryption type of the key</span>
      - <span style="color: #000000">**LAST UPDATED**</span><span style="color: #000000">: The timestamp of the key's last upload </span>
12. <span style="color: #000000">In the </span><span style="color: #000000">**Recursion**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> </span><span style="color: #000000">**recursion**</span><span style="color: #000000"> to enable recursion, and specify the following:</span>
  - <span style="color: #000000">**Resolver query timeout**</span><span style="color: #000000">: Specify the maximum time allowed for a recursive query to wait for a response before timing out. You can enter a value between 10 and 30 seconds. The default value is 10 seconds.</span>
  - <span style="color: #000000">**Lame TTL**</span><span style="color: #000000">: Specify the duration of time to cache a lame delegation or lame server. Select the period in seconds, minutes, or hours from the drop-down list. The default value is 600 seconds (ten minutes) and the maximum value is 3600 seconds (one hour). The value 0 (zero) disables lame caching and is not recommended.</span>
  - <span style="color: #000000">**Max Cache TTL**</span><span style="color: #000000">: Specify the maximum duration of time for which the name server caches positive responses. Select the period in seconds, minutes, hours, days, or weeks from the drop-down list. The minimum value is 1 second and the maximum value is 604800 seconds (7 days). The default value is 604800 seconds (7 days).</span>
  - <span style="color: #000000">**Max Negative Cache TTL**</span><span style="color: #000000">: Specify the maximum duration of time for which the name server caches negative responses. Select the period in seconds, minutes, hours, days, or weeks from the drop-down list. The default value is 10800 seconds (3 hours), minimum value is 1 second and the maximum value is 604800 seconds (7 days).</span>
13. <span style="color: #000000">In the </span><span style="color: #000000">**Local**</span><span style="color: #000000"> </span><span style="color: #000000">**Logging**</span><span style="color: #000000"> section, configure a local syslog server. For more information, see </span><span style="color: #000000">*[Local Logging (DNS)](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186714477)*</span><span style="color: #000000">. </span><span style="color: #333333">The logs can also be accessed using the </span><span style="color: #000000">*[Data Connector](https://docs.infoblox.com/display/BloxOneThreatDefense/Data+Connector)*</span><span style="color: #333333">. </span>
14. In the Local DNS Updates section create and manage DNS record updates directly on NIOS-X Servers during situations where connectivity to the Infoblox Portal is unavailable. For more information Local DNS Updates and configuration steps, see *[Configuring Local DNS Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/2282192910)*.
15. In the **DNSSEC Validation** section, you can configure DNSSEC to protect your DNS infrastructure protected. For more information on configuring DNSSEC, see *[DNSSEC Validation](https://infoblox-docs.atlassian.net/wiki/pages/createpage.action?spaceKey=bloxoneddi&title=DNSSEC%20Validation&linkCreation=true&fromPageId=186681371)*.
16. <span style="color: #000000">In the </span><span style="color: #000000">**ALLOW RECURSIVE QUERIES FROM **</span><span style="color: #000000">section, select one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Select this option to allow or deny queries from any IP addresses. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Select this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Select this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and selecting </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Select this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this option, the application allows clients with valid permission to perform recursive queries.</span>
  - <span style="color: #000000">**TSIG Key**</span><span style="color: #000000">: Select an existing TSIG. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">.</span>
17. <span style="color: #000000">In the </span><span style="color: #000000">**ROOT NAME SERVERS**</span><span style="color: #000000"> section, select one of the following options:</span>
  - <span style="color: #000000">**Use Internet root name servers**</span><span style="color: #000000">: This option is selected by default.</span>
  - <span style="color: #000000">**Use custom root name servers**</span><span style="color: #000000">: Select this option to use custom root name servers instead of the default name servers. Click </span><span style="color: #000000">**Add **</span><span style="color: #000000">and enter the following information when a new row appears:</span>
    - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter a name for the root name server.</span>
    - <span style="color: #000000">**Address**</span><span style="color: #000000">: Enter an IPv4 address for the root name server.</span>
18. <span style="color: #000000">In the </span><span style="color: #000000">**FORWARDERS**</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries under the </span><span style="color: #000000">**FORWARDERS**</span><span style="color: #000000">, and enter an IP address in the </span><span style="color: #000000">**ADDRESS **</span><span style="color: #000000">column. The field supports only IPv4 values. Select the respective check box and click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove a forwarderSelect the </span><span style="color: #000000">**Enable DNSSEC**</span><span style="color: #000000"> check box and complete the following:</span>
  - <span style="color: #000000">**Enable Validation**</span><span style="color: #000000">: If you allow the application to respond to recursive queries, you can select this check box to enable the application to validate responses to recursive queries for domains that you specify.</span>
  - <span style="color: #000000">**Accept expired signature**</span><span style="color: #000000">: Click this check box to enable the application to accept responses with signatures that have expired. Though enabling this feature might be necessary to work temporarily with zones that have not had their signatures updated in a timely fashion, note that it could also increase the vulnerability of your network to replay attacks.</span>
  - <span style="color: #000000">**TRUST ANCHORS**</span><span style="color: #000000">: Configure the DNSKEY record that holds the KSK as a trust anchor for each zone for which the application returns validated data. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> and complete the following:</span>
  - <span style="color: #000000">**ZONE**</span><span style="color: #000000">: Enter the FQDN of the domain for which the application validates responses to recursive queries.</span>
  - <span style="color: #000000">**SECURE ENTRY POINT (SEP)**</span><span style="color: #000000">: This check box is enabled by default to indicate that you are configuring a KSK.</span>
  - <span style="color: #000000">**ALGORITHM TYPE**</span><span style="color: #000000">: Select the algorithm of the DNSKEY record:</span>
    - <span style="color: #000000">RSAMD5</span>
    - <span style="color: #000000">Diffie-Hellman (This is not supported by BIND and Infoblox Universal DDI.)</span>
    - <span style="color: #000000">DSA</span>
    - <span style="color: #000000">RSASHA1</span>
    - <span style="color: #000000">DSA-NSEC3-SHA1</span>
    - <span style="color: #000000">RSASHA1-NSEC3-SHA1</span>
    - <span style="color: #000000">RSASHA-256</span>
    - <span style="color: #000000">RSASHA-512</span>
    - <span style="color: #000000">ECDSAP256SHA256</span>
    - <span style="color: #000000">ECDSAP384SHA384</span>
  - <span style="color: #000000">**PUBLIC KEY**</span><span style="color: #000000">: Paste the key into this text box. You can use either of the following commands to retrieve the key:</span>
    - <span style="color: #000000">**dig . dnskey +multiline:**</span><span style="color: #000000"> This command retrieves root zone keys and is the only public key you require for full chain of trust validation.</span>
    - <span style="color: #000000">**dig [@server_address] <zone> dnskey +multiline +dnssec: **</span><span style="color: #000000">This command retrieves public keys from the zone you specify on the server and can be used if the parent zone is not signed. Note that the aforementioned command provides you with a key you need to cross validate against other servers to ensure you have an identical key. As an alternative, you can use </span><span style="color: #0000ff">[http://data.iana.org/root-anchors/](http://data.iana.org/root-anchors/)</span><span style="color: #000000"> to retrieve signed public keys. You can find the trust anchors in formats like XML and CSR. For more information, refer to </span><span style="color: #0000ff">*[https://data.iana.org/root-anchors/old/2015-04-03/draft-icann-dnssec-trust-anchor.tx](https://data.iana.org/root-anchors/old/2015-04-03/draft-icann-dnssec-trust-anchor.txt)*</span><span style="color: #0000ff">*[t](http://data.iana.org/root-anchors/draft-icann-dnssec-trust-anchor.txt)*</span><span style="color: #000000">*.*</span>
19. <span style="color: #000000">In the </span><span style="color: #000000">** Server **</span><span style="color: #000000">section, complete the following:</span>
  - <span style="color: #000000">**Query Port**</span><span style="color: #000000">: The source port for outbound DNS queries. When you set this port to 0, it will use any available port for outbound DNS queries. The default value is 0.</span>
  - <span style="color: #000000">**Secondary AXFR query limit**</span><span style="color: #000000">: The maximum concurrent number of inbound full zone or AXFR transfers. It indicates the maximum number of DNS messages the primary server can send containing only the changed zone data, or the entire data set. The default value is 0. The minimum value is 0 and the maximum value is 65535. When you set the value to 0, the server uses a NIOS-X Server-dependent default value.</span>
  - <span style="color: #000000">**Secondary SOA query limit**</span><span style="color: #000000">: The maximum number of concurrent queries a secondary name server sends to the primary server to find out if the zone serial numbers have been changed. The default value is 0. The minimum value is 1 and the maximum value is 65535.</span>
20. <span style="color: #000000">In the </span><span style="color: #000000">**EDNS Client Subnet Configuration **</span><span style="color: #000000">section, complete the following:</span>
  - <span style="color: #000000">**Enable Recursive EDNS Client Subnet**</span>: <span style="color: #000000">Select this check box to enable recursive resolution using EDNS client subnet. This is disabled by default. If recursive EDNS client subnet is enabled, the application applies EDNS client subnet handling for queries that meet both of the following criteria:</span>
    - <span style="color: #000000">If the source prefix length is not set to zero.</span>
    - <span style="color: #000000">If the query zone name is listed in the whitelisted domains.</span>
  - <span style="color: #000000">**Enable EDNS Client Subnet Forwarding**</span><span style="color: #000000">: Select this check box to enable EDNS client subnet forwarding. If you enable ECS forwarding, all queries containing a valid EDNS client subnet option will be forwarded to the authoritative server.</span>
  - <span style="color: #000000">**QUERY ZONE PERMISSIONS**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add a list of query zone names that are subject to ECS recursion and the corresponding permission. The application adds a row to the table. Complete the following:</span>
    - <span style="color: #000000">**Zone**</span><span style="color: #000000">: Enter the zone name.</span>
    - <span style="color: #000000">**Permission**</span><span style="color: #000000">: Select </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> or </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Source Prefix**</span><span style="color: #000000">: Specify the IPv4 source prefix length. You can enter a value between 1 and 24. The default value is 24.</span>
  - <span style="color: #000000">**IPv6 Source Prefix**</span><span style="color: #000000">: Specify the IPv6 source prefix length. You can enter a value between 1 and 56. The default value is 56.</span>
21. <span style="color: #000000">In the </span><span style="color: #000000">**Zone Settings Defaults**</span><span style="color: #000000"> section, the </span><span style="color: #000000">**Use default forwarders to resolve queries for delegated subzones**</span><span style="color: #000000"> check box is selected by default. Select this check box to use the default forwarders to resolve queries for delegated subzones. Clear the check box to create custom forwarders to resolve queries for delegated subzones.</span>
22. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000">.</span>