---
title: "Adding Internal Resolvers and Internal Domains to DNS Forwarding Proxy"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35373441/Adding%20Internal%20Resolvers%20and%20Internal%20Domains%20to%20DNS%20Forwarding%20Proxy"
format: markdown
---
This guide explains how to configure internal resolvers and internal domains for the DNS Forwarding Proxy. When deploying DNS Forwarding Proxy, you can configure the service either on a standalone host or on NIOS.

- **For NIOS:** Infoblox supports adding internal resolvers for DNS Forwarding Proxy to resolve the internal/bypass domain list.
- **For Standalone DNS Forwarding Proxy:** You can configure internal domains so that queries for these domains are sent to internal resolvers instead of the Infoblox Platform.

If you are configuring internal domains on a standalone DNS Forwarding Proxy, you must also add internal resolvers to update the DNS Forwarding Proxy configuration in the cloud.  
For more details, see *[Configuring DNS Zones](https://docs.infoblox.com/space/nios90/280758860/Configuring+DNS+Zones)*.

> 📝 **Notes**
> 📝 
> 📝 - **DNS Forwarding Proxy Service Requirement:**  
> 📝 The DNS Forwarding Proxy service must be enabled before adding an internal domain list.
> 📝 - **Default Internal Domains List:**
> 📝   - When a new DNS Forwarding Proxy is created, a default internal domains list is automatically associated with it.
> 📝   - A maximum of 3,000 internal domains can be synced or associated with a DNS Forwarding Proxy.
> 📝 
> 📝 For instructions on adding internal resolvers and internal domains, see *[Configuring DNS Forwarding Proxy Settings](https://docs.infoblox.com/space/BloxOneInfrastructure/166134245)*.

### **Internal Reverse Zone Resolution in DNS Forwarding Proxy**

DFP is configured to resolve the following internal reverse mapping zones for IPv4 and IPv6 only by using internal DNS resolvers:  
   
`10.in-addr.arpa, 16.172.in-addr.arpa,  17.172.in-addr.arpa,  18.172.in-addr.arpa,  19.172.in-addr.arpa,  20.172.in-addr.arpa  21.172.in-addr.arpa,  22.172.in-addr.arpa,  23.172.in-addr.arpa,  24.172.in-addr.arpa,  25.172.in-addr.arpa,  26.172.in-addr.arpa,  27.172.in-addr.arpa  28.172.in-addr.arpa,  29.172.in-addr.arpa,  30.172.in-addr.arpa,  31.172.in-addr.arpa,  168.192.in-addr.arpa, 254.169.in-addr.arpa, 8.e.f.ip6.arpa  9.e.f.ip6.arpa,  a.e.f.ip6.arpa,  b.e.f.ip6.arpa,  c.f.ip6.arpa, d.f.ip6.arpa`

The user must configure one or more internal resolvers under the DNS Forwarding Proxy settings in the Infoblox Portal in order to enable DNS Forwarding Proxy to resolve these internal reverse mapping zones locally.

> ℹ️ These private reverse zones are automatically included in the internal domains list, eliminating the need for further configuration.

## **Adding an Internal Domains List to a DNS Forwarding Proxy**

To add an internal domains list to a DNS Forwarding Proxy (DFP), do the following:

1. In the Infoblolx Portal, navigate to the Protocol Service page (**Network** > **Services & Servers** > **Protocol Service**).

2. From among the list of of services, select the DNS Forwarding Proxy service where you want to add the internal domains list.
3. Click **Edit** in the action bar at the top of the page to open up the *DNS Forwarding Proxy* wizard. Alternatvely, click the three-dot menu (**⋯**) associated with the desired DNS Forwarding Proxy.Ckick **Edit** from among the menu options.
4. In the** ***DNS Forwarding Proxy* wizard, click** DNS Forwarding Proxy**, located in the side menu.
5. Click Internal Domains List to expand the configuration section.
6. Click **Add** to select and add an internal domains list to the DNS Forwarding Proxy configuration.
7. Click **Finish** after the internal domains list has been successfully added.

For information on importing an internal domains list, see *[Importing an Internal Domains List](https://docs.infoblox.com/space/BloxOneThreatDefense/35375118/Importing+an+Internal+Domains+List)**.*