---
title: "Creating a Primary Zone"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186681644/Creating%20a%20Primary%20Zone"
format: markdown
---
<span style="color: #000000">A primary zone stores the master copy of the zone data. Primary zones are organized within DNS views. For more information on DNS Zones, see </span><span style="color: #000000">*[Configuring DNS Zones](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186811177)*</span><span style="color: #000000">. </span>

<span style="color: #000000">To create a primary zone, complete the following:</span>

1. From the Cloud Services Portal, click **Network** > <span style="color: #000000">**DNS **</span>> <span style="color: #000000">**Zones.**</span>
2. <span style="color: #000000">Create a DNS view or click an existing DNS view. For more information about creating a DNS view, see </span><span style="color: #000000">*[Configuring DNS Views](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186680934)*</span><span style="color: #000000">.</span>
3. <span style="color: #000000">On the </span><span style="color: #000000">*Zones *</span><span style="color: #000000">page, click </span><span style="color: #000000">**Create **</span><span style="color: #000000">and select </span><span style="color: #000000">**Primary Zone **</span><span style="color: #000000">from the drop-down list.</span>
4. <span style="color: #000000">On the </span><span style="color: #000000">*Create Primary Zone*</span><span style="color: #000000"> page, specify the following:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter the domain name for the zone. </span>
    - To create an IPv4 reverse-mapping zone, specify [in-addr.arpa](http://in-addr.arpa/) as the top-level reverse-mapping zone while specifying a name for the zone.
    - To create an IPv6 reverse-mapping zone, specify [ip6.arpa](http://ip6.arpa/) as the top-level reverse-mapping zone while specifying a name for the zone.
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Enter additional details about the zone.</span>
  - <span style="color: #000000">**Disable for DNS Protocol**</span><span style="color: #000000">: Select this check box to temporarily disable this zone. For information, see </span><span style="color: #000000">*[Enabling and Disabling Zones](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617648)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Notify External Secondary DNS Servers**</span><span style="color: #000000">: Select this check box to notify external secondary DNS servers that a primary zone has been created. </span>
  - <span style="color: #000000">**Tags**</span><span style="color: #000000">: Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to associate keys with values. Specify the following details:</span>
    - <span style="color: #000000">**KEY**</span><span style="color: #000000">: Enter a meaningful name for the key, such as a location or a department.  </span>
    - <span style="color: #000000">**VALUE**</span><span style="color: #000000">: Enter a value for the key such as San Jose (for location), or Accounts (for department).  </span>
5. <span style="color: #000000">Select </span><span style="color: #000000">**DNS AUTHORITATIVE SERVERS**</span><span style="color: #000000"> from the list. You can also define zones without assigning DNS servers to them. This is particularly helpful during pre-deployment provisioning and during troubleshooting activities. </span>
6. <span style="color: #000000">Configure the Zone Settings Defaults. The Zone Settings Defaults are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617130)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values for each of the following:</span>
  - <span style="color: #000000">**Serial Number**</span><span style="color: #000000">: Specify a serial number.</span>
  - <span style="color: #000000">**Refresh**</span><span style="color: #000000">: Specify the value and choose Hours,  Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Retry**</span><span style="color: #000000">: Specify the value and choose Hours, Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Expire**</span><span style="color: #000000">: Specify the value and choose Days, Hours, Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Default TTL**</span><span style="color: #000000">: Specify the value and choose Hours, Minutes, or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**Negative-caching TTL**</span><span style="color: #000000">: Specify the value and choose Minutes or Seconds from the drop-down list.</span>
  - <span style="color: #000000">**EMAIL ADDRESS (FOR SOA RNAME field)**</span><span style="color: #000000">: Specify an email address for the SOA RNAME field.</span>
  - <span style="color: #000000">Use default forwarders to resolve queries for delegated zones. Select the check box to use the default forwarders for delegated zones.</span>
7. <span style="color: #000000">Configure the Queries. The queries are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617130)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ALLOW QUERIES FROM**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:   </span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny queries from any IP addresses or networks. The application replies to queries from all clients. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the client from which the query originates. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add a network to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL that you want to use. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, the application automatically displays the named ACL. When you select this, the application replies to DNS queries from clients matching the ACL. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the selected named ACL.</span>
  - <span style="color: #000000">**TSIG**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
8. <span style="color: #000000">Configure </span><span style="color: #000000">**DNSSEC Signing**</span><span style="color: #000000">. For more information, </span><span style="color: #000000">*[DNSSEC Signing](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/1540620608)*</span><span style="color: #000000">.</span>
9. <span style="color: #000000">Configure the Zone transfers. The queries are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617130)*</span></u><span style="color: #000000">. Alternatively, toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ACCEPT ZONE TRANSFER REQUESTS FROM**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list:</span>
  - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny queries from any IP addresses or networks. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. In that case, the application replies to queries from all clients. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
  - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you choose this, the application allows servers that have the </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the chosen named ACL.</span>
  - <span style="color: #000000">**TSIG**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
10. <span style="color: #000000">Configure dynamic updates. The dynamic updates are inherited from Global DNS Properties. For more information, see </span><u><span style="color: #000000">*[Configuring Global DNS Properties](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186617130)*</span></u><span style="color: #000000">. </span>
  - <span style="color: #000000">**Allow GSS-TSIG-signed updates**</span><span style="color: #000000">: Toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000">, and select the check box to allow GSS-TSIG-signed updates. GSS-TSIG (Generic Security Service Algorithm for Secret Key Transaction) is used to authenticate DDNS updates. For more information, see </span><span style="color: #000000">*[Configuring GSS-TSIG](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186876219)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**ALLOW DYNAMIC UPDATES**</span><span style="color: #000000">: Toggle </span><span style="color: #000000">**Inherit**</span><span style="color: #000000"> to </span><span style="color: #000000">**Off**</span><span style="color: #000000"> and configure the values in the </span><span style="color: #000000">**ALLOW DYNAMIC UPDATES**</span><span style="color: #000000"> section. Click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add or </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove the entries. Choose one of the following from the </span><span style="color: #000000">**TYPE**</span><span style="color: #000000"> drop-down list: </span>
    - <span style="color: #000000">**Any Address/Network**</span><span style="color: #000000">: Choose this option to allow or deny the application to send zone transfers to any IP address or network. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
    - <span style="color: #000000">**IPv4 Address**</span><span style="color: #000000">: Choose this option to add an IPv4 address. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter the IP address of the remote server. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays Allow by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
    - <span style="color: #000000">**IPv4 Network**</span><span style="color: #000000">: Choose this option to add an IPv4 network address to the list. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and enter an IPv4 network address and type a netmask. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
    - <span style="color: #000000">**Named ACL**</span><span style="color: #000000">: Choose this option to add a named ACL. Click the </span><span style="color: #000000">**VALUE**</span><span style="color: #000000"> field and the list of named ACLs are displayed. If you have only one named ACL, it is displayed automatically. When you select this, the application allows servers permission to send and receive DNS zone transfer data. You can click </span><span style="color: #000000">**Clear**</span><span style="color: #000000"> to remove the chosen named ACL.</span>
    - <span style="color: #000000">**TSIG**</span><span style="color: #000000">: Select an existing TSIG Key. For more information, see </span><span style="color: #000000">*[Configuring TSIG Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186778455)*</span><span style="color: #000000">. The </span><span style="color: #000000">**PERMISSION**</span><span style="color: #000000"> column displays </span><span style="color: #000000">**Allow**</span><span style="color: #000000"> by default. You can change it to </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> by clicking the field and choosing </span><span style="color: #000000">**Deny**</span><span style="color: #000000"> from the drop-down list.</span>
11. <span style="color: #172b4d">An </span>`rdatatype`<span style="color: #172b4d"> (short for resource record type) refers to the specific type of resource record (RR) in the DNS. Each resource record in DNS has an associated type that indicates the kind of data it holds for example type A, the IPv4 address of a NIOS-X Server, or type MX , how to route mail. An </span>`rdataset`<span style="color: #172b4d"> refers to a set of resource records (RRs) of the same type for a specific domain name in the Domain Name System (DNS). An </span>`rdatatype`<span style="color: #172b4d"> (short for resource record type) refers to the specific type of resource record (RR) in the DNS. Each resource record in DNS has an associated type that indicates the kind of data it holds for example type A, the IPv4 address of a NIOS-X Server, or type MX , how to route mail. An </span>`rdataset`<span style="color: #172b4d"> refers to a set of resource records (RRs) of the same type for a specific domain name in the Domain Name System (DNS). </span>Excessively large `rdatasets` or large numbers of `rrtypes` can slow down query processing, therefore limits can be set on a per-zone basis. The value, “0”, removes any upper limit. However, this may result in reduced performance. Configure the following settings:
  - <span style="color: #000000">**Max Records per Type**</span><span style="color: #000000">: Specify a numeric value for maximum records per type. The default value is 2000.</span>
  - <span style="color: #000000">**Max Types per Name**</span><span style="color: #000000">: Specify a numeric value for maximum types per name. The default value is 100.</span>
12. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000"> to save.</span>
  After a primary zone is created, you can add resource records to it. For more information, see *[Configuring Resource Records](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186648422)*.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">An authoritative reverse-mapping zone is an area of network space for which one or more name servers—primary and secondary—have the responsibility to respond to address-to-name queries. Infoblox supports reverse-mapping zones for IPv4 addresses. You can add </span><span style="color: #000000">[in-addr.arpa](http://in-addr.arpa)</span><span style="color: #000000"> as the top-level reverse-mapping zone. Note that you cannot add these zones using their IP addresses or netmasks, however, you can add them by name </span><span style="color: #000000">[in-addr.arpa](http://in-addr.arpa)</span><span style="color: #000000"> respectively.</span>
> ⚠️ 
> ⚠️ <span style="color: #000000">*RFC 2317, Classless IN-ADDR.ARPA *</span><span style="color: #000000">delegation is an IETF (Internet Engineering Task Force) document that describes a method of delegating parts of the DNS IPv4 reverse-mapping tree that corresponds to subnets smaller than a /24 (from a /25 to a /31). The DNS IPv4 reverse-mapping tree has nodes broken at octet boundaries of IP addresses, which correspond to the old classful network masks. So, IPv4 reverse-mapping zones usually fall on /8, /16, or /24 boundaries.</span>
> ⚠️ 
> ⚠️ <span style="color: #000000">To create a primary authoritative reverse mapping zone, add </span><span style="color: #000000">[in-addr.arpa](http://in-addr.arpa)</span><span style="color: #000000"> as the top-level reverse mapping zone and specify the domain in the </span><span style="color: #000000">**Name**</span><span style="color: #000000"> field.</span>

> ❌ **Warning**
> ❌ 
> ❌ The subdomains starting with **ns.b1ddi** and **b1ddi** are reserved and cannot be used as a prefix for the names of zones and resource records.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ When creating or modifying a zone managed by NIOS, if you **Inherit** or **Override** one of the fields Refresh, Retry, Expire, DefaultTTL, and Negative-caching TTL, the other fields will automatically follow the same settings. You cannot **Inherit** or **Override** a single field selectively.