---
title: "Enabling a Grid Member to Forward Recursive Queries Using DFP"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35404082/Enabling%20a%20Grid%20Member%20to%20Forward%20Recursive%20Queries%20Using%20DFP"
format: markdown
---
## <span style="color: #000000">Enabling a Grid Member to Forward Recursive Queries to Infoblox Threat Defense Using DFP</span>

<span style="color: #000000">DFP is a NIOS service which automatically handles DNS query forwarding. You can start and stop the DFP service just like other NIOS services. You can configure the connection between NIOS and Infoblox Portal by using the </span><span style="color: #000000">**CSP Config**</span><span style="color: #000000"> tab in </span><span style="color: #000000">*Grid Properties*</span><span style="color: #000000"> Editor or </span><span style="color: #000000">*Grid Member Properties*</span><span style="color: #000000"> Editor.</span>

<span style="color: #000000">To enable a Grid member to forward recursive queries to Infoblox Threat Defense, complete the following:</span>  


> ⚠️ ### Note
> ⚠️ 
> ⚠️ Steps 1 though 6, below, are not mandatory when <u>only</u> enabling forward recursive queries on a grid member.

1. <span style="color: #000000">Log in to the Infoblox Portal. </span>
2. <span style="color: #000000">Create a join token by following the instructions in the </span><u><span style="color: #000000">*[Configuring Join Tokens ](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/87229997)*</span></u>section of the <span style="color: #000000">Infoblox</span> Threat Defense documentation. In an HA environment, two on-prem hosts are created. You must ensure that the configurations for both these on-prem hosts are the same for the HA nodes to work seamlessly.
3. Log in to Grid Manager.
4. On the **Grid** tab, click the **Grid Manager** tab > **Grid Properties** > **Edit**.
5. In *Grid Properties* *Editor*, click the **CSP Config **tab and complete the following:
  - **Join Token: **Configure the join token that you created in the Infoblox  Portal in step 2. However, if the field is empty, the platform connection is not to be terminated.
  - **CSP Resolver: **Displays the IP address of the local DNS resolver. This IP address or DNS is used to resolve Infoblox domains when the DNS Forwarding Proxy service starts. You must configure at least one external resolver that will be used to resolve all required domains. If you do not enter an IP address, 52.119.40.100 is taken as the default.
  - **HTTP proxy**: Enter the URL of the proxy server in the http://<*IP*/*host*>:<*port*> format. When you update the HTTP proxy, the NIOS on-prem agent updates it to the other on-prem containers by restarting the containers at a specific interval which can cause a maximum delay of 15 minutes.
6. Click **Save & Close**.
7. **Member**: From the **Grid** tab, select the **Grid Manager** tab > **Members** tab > *member *checkbox > Edit icon.
8. In the *Grid Member Properties* *Editor*, click the **CSP Config **tab, and then complete the following. To override an inherited property, click **Override** next to it and enter the value for the appropriate fields if you do not want to inherit the values from the Grid. Once you override, the settings are applicable only at the member level.
  1. **Join Token**: Displays the join token value that is inherited from the Grid. However, if the field is empty, the platform connection is not to be terminated.
  2. **CSP Resolver**: Displays the Infoblox  Portal  resolver value that is inherited from the Grid.
  3. **HTTP Proxy**: Displays the URL that is inherited from the Grid.
  4. **Standalone:** Select this option when the member is standalone.
    1. **Access Key**: You cannot edit the value of this field; you can only clear it. However, clearing the access key value does not terminate the platform connection.
  5. **HA Enabled: **Select this option when the member is an HA.
    1. **Access Key**: You cannot edit the value of this field; you can only clear it. In case of a NIOS upgrade, the access keys are the same for both the active and passive nodes.
9. Click **Save & Close**.
10. On the **Grid** tab, select the **Grid Manager **tab > **DFP **tab > *member *checkbox > Edit icon.
11. In *Member DFP Properties* editor, select the **Fallback to the default resolution process if **<span style="color: #000000">**Infoblox**</span>** Threat Defense does not respond **checkbox to forward recursive queries to the local root name servers in case <span style="color: #000000">Infoblox</span> Threat Defense fails or if <span style="color: #000000">Infoblox</span> Threat Defense fails to resolve recursive queries. For newly configured DNS Forwarding Proxies in NIOS, Infoblox recommends that you keep this option selected until you have verified that the NIOS proxies are functioning properly. In the Infoblox  Portal, go to **Configure **>** IPAM/DHCP** > **Hosts** to ensure that the statuses for the NIOS proxies that you have registered are active.

> ⚠️ - <span style="color: #000000">If you have upgraded to NIOS 8.5.x with DNS Forwarding Proxy enabled on any node, Infoblox recommends that you do not remove the on-prem hosts from the Infoblox  Portal. This is because NIOS preserves the access key during the upgrade and the NIOS Grid member connects to the Infoblox Portal using the same access key.</span>
> ⚠️ - You must create a join token to authenticate a virtual DNS Forwarding Proxy for establishing a connection to the platform. For more information on creating a join token, see the <u><span style="color: #000000">*[Configuring Join Tokens](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/87229997)*</span></u> section in the <span style="color: #000000">Infoblox</span> Threat Defense documentation.
> ⚠️ - If you have upgraded NIOS, the value of the **Access Key** field is the same as the API key that is displayed in the Infoblox <span style="color: #000000"> Portal.</span>

<span style="color: #000000">For additional information, see </span><span style="color: #000000">*[Enabling a Grid Member](https://docs.infoblox.com/space/nios90/280665882/Enabling+Recursive+Queries)*</span><span style="color: #000000">* *</span><span style="color: #000000">in the NIOS 9.0 documentation. </span>