---
title: "Creating a Secondary Zone"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186681610/Creating%20a%20Secondary%20Zone"
format: markdown
---
<span style="color: #000000">A secondary zone is a read-only copy of the primary zone that is stored on a different server. The secondary zone cannot process updates and can only retrieve updates from the primary zone. Secondary zones are organized within DNS views. For more information on DNS Zones, see </span><span style="color: #000000">*[Configuring DNS Zones](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186811177)*</span><span style="color: #000000">. </span>

<span style="color: #000000">To create a secondary zone, complete the following:</span>

1. From the Cloud Services Portal, click **Network** > <span style="color: #000000">**DNS **</span>> <span style="color: #000000">**Zones.**</span>
2. <span style="color: #000000">Create a DNS view or click an existing DNS view. For more information about creating a DNS view, see </span><span style="color: #000000">*[Configuring DNS Views](https://infoblox-docs.atlassian.net/wiki/display/ddiadminguidensdraft/Configuring+DNS+Views)*</span><span style="color: #000000">.</span>
3. <span style="color: #000000">On the </span><span style="color: #000000">*Zones *</span><span style="color: #000000">page, click </span><span style="color: #000000">**Create **</span><span style="color: #000000">and choose </span><span style="color: #000000">**Secondary Zone **</span><span style="color: #000000">from the drop-down list.</span>
4. <span style="color: #000000">On the </span><span style="color: #000000">*Create Secondary Zone*</span><span style="color: #000000"> page, specify the following:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter the domain name for the zone. </span>
    - To create an IPv4 reverse-mapping zone, specify [in-addr.arpa](http://in-addr.arpa/) as the top-level reverse-mapping zone while specifying a name for the zone.
    - To create an IPv6 reverse-mapping zone, specify [ip6.arpa](http://ip6.arpa/) as the top-level reverse-mapping zone while specifying a name for the zone.
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Enter additional details about the zone.</span>
  - <span style="color: #000000">**Disable for DNS Protocol**</span><span style="color: #000000">: Click this check box to temporarily disable this zone. For information, see </span><span style="color: #000000">*[Enabling and Disabling Zones](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617648)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Notify External Secondary DNS Servers**</span><span style="color: #000000">: Select this check box to notify external secondary DNS servers that a secondary zone has been created. </span>
  - <span style="color: #000000">**Tags**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to associate keys with values. Specify the following details:</span>
    - <span style="color: #000000">**KEY**</span><span style="color: #000000">: Enter a meaningful name for the key, such as a location or a department.  </span>
    - <span style="color: #000000">**VALUE**</span><span style="color: #000000">: Enter a value for the key such as San Jose (for location), or Accounts (for department).   </span>
5. <span style="color: #000000">Define DNS server groups for the zone. Choose either DNS Server Group, External Primary, or Internal Secondary from the list. For information on specifying authoritative DNS server groups, see </span><span style="color: #000000">*[Configuring DNS Server Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186746079)*</span><span style="color: #000000">.</span>
6. <span style="color: #000000">Configure the Primary (Master) DNS servers. Configure the following settings for the External Primary DNS server:   </span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Specify the name of the server.</span>
  - <span style="color: #000000">**Address**</span><span style="color: #000000">: Specify an IPv4 address.</span>
  - <span style="color: #000000">**Use TSIG**</span><span style="color: #000000">: Select this check box to use the standards-based TSIG key that uses the one-way hash function to secure transfers between name servers. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">.</span>
    - <span style="color: #000000">**New TSIG**</span><span style="color: #000000">: Choose this option to create a new TSIG key. Configure the following for a new TSIG key:</span>
      - <span style="color: #000000">**Key Name**</span><span style="color: #000000">: Specify a name for the key.</span>
      - <span style="color: #000000">**Algorithm**</span><span style="color: #000000">: Choose one of the following algorithm from the drop-down: HMAC-MD5, HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512.</span>
      - <span style="color: #000000">**Secret**</span><span style="color: #000000">: Specify a value for the secret. The value must be a Base64 encoded string. Alternatively, click </span><span style="color: #000000">**Generate**</span><span style="color: #000000"> to automatically generate a unique value.</span>
      - <span style="color: #000000">**Description**</span><span style="color: #000000">: Specify a description for the key.</span>
    - <span style="color: #000000">**Existing TSIG**</span><span style="color: #000000">: Select an existing TSIG Key from the drop-down. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. </span>
7. <span style="color: #000000">Configure the Zone transfers. The queries are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://infoblox-docs.atlassian.net/wiki/display/ddiadminguidensdraft/Configuring+Global+DNS+Properties)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ACCEPT ZONE TRANSFER REQUESTS FROM**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
8. <span style="color: #172b4d">An </span>`rdatatype`<span style="color: #172b4d"> (short for resource record type) refers to the specific type of resource record (RR) in the DNS. Each resource record in DNS has an associated type that indicates the kind of data it holds for example type A, the IPv4 address of a NIOS-X Server, or type MX , how to route mail. An </span>`rdataset`<span style="color: #172b4d"> refers to a set of resource records (RRs) of the same type for a specific domain name in the Domain Name System (DNS). </span>Excessively large `rdatasets` or large numbers of `rrtypes` can slow down query processing, therefore limits can be set on a per-zone basis. The value, “0”, removes any upper limit. However, this may result in reduced performance. Configure the following settings:
  - <span style="color: #000000">**Max Records per Type**</span><span style="color: #000000">: Specify a numeric value for maximum records per type. The default value is 2000.</span>
  - <span style="color: #000000">**Max Types per Name**</span><span style="color: #000000">: Specify a numeric value for maximum types per name. The default value is 100.</span>
9. <span style="color: #000000">**Synchronize secondary zone content**</span><span style="color: #000000">: </span>By default, a secondary DNS zone receives its records directly from an external primary server through standard zone transfer mechanisms (AXFR/IXFR). The secondary server uses this data to resolve DNS queries, but the transferred records are not stored or displayed in the Infoblox portal. As a result, administrators can rely on the secondary server for resolution, but they have no visibility into the actual zone content from within the Infoblox management interface. When **Synchronize Secondary Zone Content** is enabled, Infoblox synchronizes the records of the secondary zone from the supported secondary server and imports them into the Infoblox portal. This allows administrators to view the full set of resource records associated with the secondary zone directly in the portal, alongside other managed DNS objects. The feature is designed to enhances operational visibility, troubleshooting, auditing, and consistency checks across primary and secondary DNS servers. The synchronization may take up to 15 minutes.
10. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000"> to save.</span>