---
title: "Best Practices for DFP on NIOS"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35373309/Best%20Practices%20for%20DFP%20on%20NIOS"
format: markdown
---
If your network infrastructure consists of an on-prem Infoblox Grid, you can select any Grid member to function as a DNS forwarder. Ensure that you configure your firewall to allow that Grid member to communicate with external DNS servers and enable DNS recursion on the member.   


<span style="color: #000000">DFP (DNS Forwarding Proxy) on NIOS is the preferred way to send DNS queries to Infoblox Platform. DFP is a NIOS service and it automatically handles DNS query forwarding. You can start and stop the DFP service just like other NIOS services. You can configure the connection between NIOS and Infoblox Platform by using the new </span><span style="color: #000000">**CSP Config**</span><span style="color: #000000"> tab in </span><span style="color: #000000">*Grid Properties*</span><span style="color: #000000"> Editor or </span><span style="color: #000000">*Grid Member Properties*</span><span style="color: #000000"> Editor. For</span> additional information on DFP and how forwarding works, see <span style="color: #000000">*[Enabling a Grid Member to Forward Recursive Queries](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35404082)*</span>.

A recursive query requires the appliance to return requested DNS data, or locate the data through queries to other servers. When a NIOS appliance receives a query for DNS data it does not have and you have enabled recursive queries, it first sends a query to any specified forwarders. If a forwarder does not respond (and you have disabled the **Use** **Forwarders** **Only** option in the **Forwarders** tab of the *Member* *DNS* *Properties* editor), the appliance sends a non-recursive query to specified internal root servers. If no internal root servers are configured, the appliance sends a non-recursive query to the Internet root servers. For information on specifying root name servers, see *[About Root Name Servers](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280405807)*.

You can enable recursion for a Grid, individual Grid members, and DNS views. For information about enabling recursion in a DNS view, see *[Configuring DNS Views](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280665456)*. If you do not enable recursion, the appliance denies recursive queries from all clients.

> ❌ <span style="color: #000000">**Warning**</span>  
> ❌ <span style="color: #000000">On the host, if you have configured delegations in your subzones, ensure that you select the </span><span style="color: #000000">**Don't use forwarders to resolve queries in subzones**</span><span style="color: #000000"> check box when you configure the parent’s authoritative zone properties. Otherwise, delegations will not function properly. Because forwarding has precedence over delegation, the query will be sent to the Infoblox Platform instead of the delegated servers. For information about how to configure authoritative zone properties, see </span><span style="color: #0000ff">*[Configuring Authoritative Zone Properties](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280763330)*</span><span style="color: #000000">. For information about delegations, see </span><span style="color: #0000ff">*[About Authority Delegation](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280667711)*</span><span style="color: #000000">.</span>

  


> ⚠️ ### Note
> ⚠️ 
> ⚠️ - If the initial query resolves to a CNAME, then BIND will resolve the CNAME again. At this point, if the CNAME gets a hit on the security policy, then it responds based on the security action assigned to it. This is the default behavior for NIOS with DFP and NIOS-X with DFP+DNS enabled on it.
> ⚠️ - It is recommended to provide Join token at Grid member level, and not advisable to provide Join Token at Grid level (as that will try and connect all members of the Grid to the Infoblox Portal and not just the NIOS members with DNS Forwarding Proxy).

For information on enabling recursive queries using Grid Member, NIOS 9.0, NIOS 8.6,  or NIOS 8.5, see the following:

- <span style="color: #000000">**Enabling a Grid Member to Forward Recursive Queries to Infoblox Threat Defense Using DFP**</span>

<span style="color: #000000">DFP is a NIOS service which automatically handles DNS query forwarding. You can start and stop the DFP service just like other NIOS services. You can configure the connection between NIOS and the Infoblox  Portal by using the </span><span style="color: #000000">**CSP Config**</span><span style="color: #000000"> tab in </span><span style="color: #000000">*Grid Properties*</span><span style="color: #000000"> Editor or </span><span style="color: #000000">*Grid Member Properties*</span><span style="color: #000000"> Editor. To enable a Grid member to forward recursive queries to Infoblox Threat Defense, see </span><span style="color: #000000">*[Enabling a Grid Member to Forward Recursive Queries Using DFP](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35404082)*</span><span style="color: #000000">.</span>

- <span style="color: #000000">**Enabling Recursive Queries in NIOS 9.0**</span>

<span style="color: #000000">To enable recursion on the Grid or member in NIOS 9.0, see </span><span style="color: #000000">*[Enabling Recursive Queries in NIOS 9.0](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280665882)*</span><span style="color: #000000">.</span>

- <span style="color: #000000">**Enabling Recursive Queries in NIOS 8.6**</span>

<span style="color: #000000">To enable recursion on the Grid or member in NIOS 8.6, see </span><span style="color: #000000">*[Enabling Recursive Queries in NIOS 8.6](https://infoblox-docs.atlassian.net/wiki/spaces/nios86/pages/1102840231)*</span><span style="color: #000000">.</span>

- <span style="color: #000000">**Enabling Recursive Queries in NIOS 8.5**</span>

To enable recursion on the Grid or member in NIOS 8.5, see <span style="color: #000000">*[Enabling Recursive Queries in NIOS 8.5](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448674)*</span><span style="color: #000000">.</span>

## DNS Fallback

<span style="color: #201f1e">Infoblox strongly recommends that you configure DNS fallback. For information, see </span><span style="color: #201f1e">*[Using DNS Fallback](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/337150481)*</span><span style="color: #201f1e">.</span>

## Deployment of Multiple DFPs

Infoblox recommends deploying more than one DFP instance per site or location whenever possible. 

## DFP Reporting

To see the end client IP address in the DNS logs and Security logs in the Infoblox Portal, make sure that **Add client IP**, **MAC addresses, and DNS View name to outgoing recursive queries** and **Copy client IP**,** MAC addresses, and DNS View name to outgoing recursive queries** are checked depending on the DNS infrastructure. For information, see *[Using Forwarders](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/317784896)* in the NIOS 9.0 documentation.

> ⚠️ ### Note
> ⚠️ 
> ⚠️ <span style="color: #000000"> In some scenarios the end client IP address may not be visible. For example, when </span><span style="color: #000000">*Fault Tolerant Caching*</span><span style="color: #000000"> is enabled in NIOS or in </span><span style="color: #000000">*Prefetch*</span><span style="color: #000000"> </span><span style="color: #000000">*query*</span><span style="color: #000000">.</span>

## DNSSEC

<span style="color: #201f1e">DFP can have problems when DNSSEC is enabled on NIOS. For more details, see </span><u>*[Enabling DNS Forwarding Proxy to Work with DNSSEC](https://infoblox-docs.atlassian.net/wiki/spaces/nios90/pages/280762310)*</u><span style="color: #201f1e">.</span>