---
title: "Configuring DNS over TLS and DNS over HTTPS Services"
canonical: "https://docs.infoblox.com/space/nios85/35418166/Configuring%20DNS%20over%20TLS%20and%20DNS%20over%20HTTPS%20Services"
format: markdown
---
<span style="color: #000000">DNS queries and responses sent over port 53 without encryption are vulnerable to spoofing and eavesdropping. This issue is addressed in NIOS appliances that have DNS over TLS (Transport Layer Security) and DNS over HTTPS services enabled. These features encrypt DNS queries and responses to secure communication between a DNS server and a DNS client.</span>

<span style="color: #000000">This topic details the requirements that NIOS appliances must meet for enabling the DNS over TLS and DNS over HTTPS services and has instructions to configure these services. The sections covered in this topic are as follows:</span>

> Macro (toc)

# Licensing and Certificate Requirements

<span style="color: #000000">DNS over TLS and DNS over HTTPS require the vDCA (virtual DNS Cache Acceleration) or vADP (virtual Advanced DNS Protection Software) service to be licensed and enabled. If the DNS Cache Acceleration and/or Advanced DNS Protection Software services are not enabled, the DNS over TLS and DNS over HTTPS features will not work even if they are enabled.</span><span style="color: #000000"> For more information about DNS Cache Acceleration and Advanced DNS Protection Software (threat protection), see </span>[*<span style="color: #000000">Configuring DNS Cache Acceleration</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448886)<span style="color: #000000"> and </span>*[<span style="color: #000000">About Infoblox Advanced DNS Protection</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35447268)*<span style="color: #000000"> respectively. </span>

<span style="color: #000000">The DNS over TLS or the DNS over HTTPS service uses the same self-signed certificate that NIOS generates for HTTPS communication when it first starts. You can also generate a certificate signing request (CSR) and use it to obtain a signed certificate from your own trusted certificate authority (CA). For more information, see </span>[*<span style="color: #000000">Generating Certificate Signing Requests</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35381871/Managing+Certificates#ManagingCertificates-GeneratingCertificateSigningRequests)<span style="color: #000000">.</span>

<span style="color: #000000">The certificate is provisioned for each member. For more information about certificates, see </span>[*<span style="color: #000000">Managing Certificates</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35381871)<span style="color: #000000">.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">NIOS generates a new self-signed certificate when the host name or the IP address of the member is changed or when a Grid Master Candidate is promoted. If the DNS over TLS or DNS over HTTPS feature is enabled on a member, then every time a new self-signed certificate, HTTPS certificate, or a CA certificate is generated, the DNS over TLS service or the DNS over HTTPS service (depending on which feature is enabled) automatically restarts to upload the new certificate.</span>

# Base Configuration Requirements

<span style="color: #000000">NIOS appliances must have the required base memory configuration to enable the DNS over TLS and the DNS over HTTPS features on their members. If the appliances do not meet the required criteria, the options to configure these features are not displayed in the </span>*<span style="color: #000000">Member DNS Properties</span>*<span style="color: #000000"> editor. The following table lists the base configuration required for enabling these features on IB-FLEX appliances.</span>

> ❌ **Warning**
> ❌ 
> ❌ The numbers in the following tables are for IB-FLEX appliances only. For information about CPU and memory requirements of NIOS appliances other than IB-FLEX, see the *NIOS Release Notes*.

| **IB-FLEX Flavor Configuration** | **Total CPU** | **Total **<span style="color: #000000">**System **</span>**Memory in GB (With virtual Advanced DNS Protection Software only)** | **Total **<span style="color: #000000">**System **</span>**Memory in GB (With virtual DNS Cache Acceleration and virtual Advanced DNS Protection Software)** | **Maximum Number of Concurrent Sessions Supported** | **Grid Master Capable** |
| --- | --- | --- | --- | --- | --- |
| <span style="color: #000000">Small</span>  
<span style="color: #000000">recursive DNS (with acceleration)</span> | <span style="color: #000000">10</span> | <span style="color: #000000">32</span> | <span style="color: #000000">32</span> | <span style="color: #000000">For vDCA only: 120,000</span><br><span style="color: #000000">For vADP only: 50,000</span><br><span style="color: #000000">For vDCA and vADP: 120,000</span> | <span style="color: #000000">No</span> |
| <span style="color: #000000">Medium</span>  
<span style="color: #000000">recursive DNS (with acceleration)</span> | <span style="color: #000000">16</span> | <span style="color: #000000">64</span> | <span style="color: #000000">40</span> | <span style="color: #000000">For vDCA only: 150,000</span><br><span style="color: #000000">For vADP only: 60,000</span><br><span style="color: #000000">For vDCA and vADP: 150,000</span> | <span style="color: #000000">No</span> |
| <span style="color: #000000">Large</span>  
<span style="color: #000000">recursive DNS (with acceleration)</span> | <span style="color: #000000">26</span> | <span style="color: #000000">80</span> | <span style="color: #000000">50</span> | <span style="color: #000000">For vDCA only: 240,000</span><br><span style="color: #000000">For vADP only: 80,000</span><br><span style="color: #000000">For vDCA and vADP: 240,000</span> | <span style="color: #000000">No</span> |

The following table lists the maximum number of concurrent sessions supported by different NIOS appliance models (physical and virtual). For information about CPU and memory requirements, see the NIOS Release Notes.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">If the available memory does not meet the requirement defined in the above table, you may observe unexpected behavior. Infoblox recommends that you allocate slightly more memory to ensure that memory associated with the hypervisor is also accounted for.</span>

| **NIOS Appliance**  
**(Physical and Virtual)** | **Maximum Number of Concurrent Sessions Supported** |
| --- | --- |
| IB-14x5 | <span style="color: #000000">For vADP only: 50,000</span> |
| IB-22x5 | <span style="color: #000000">For vDCA only: 150,000</span><br><span style="color: #000000">For vADP only: 60,000</span><br><span style="color: #000000">For vDCA and vADP: 150,000</span> |
| IB-40x5 | <span style="color: #000000">For vDCA only: 240,000</span><br><span style="color: #000000">For vADP only: 80,000</span><br><span style="color: #000000">For vDCA and vADP: 240,000</span> |

> ⚠️ **Note**
> ⚠️ 
> ⚠️ In an HA setup, ensure that both the active and passive nodes have the memory configuration required to enable the DNS over TLS or the DNS over HTTPS feature. If you enable the feature on an active node that has the required memory footprint but the passive node does not, then in case of a failover, the DNS over TLS or the DNS over HTTPS service does not start on the new active node. Therefore, requests coming to the DNS over TLS or the DNS over HTTPS stream are not honored.

## Configuration Requirements if Parental Control is Enabled

NIOS appliances require additional memory if you intend to run DNS over TLS and/or DNS over HTTPS along with the Parental Control features such as proxy RPZ passthru, DCA subscriber query count logging, and DCA subscriber allowed and blocked listing simultaneously. <span style="color: #000000">The following table lists the base configuration required on IB-FLEX appliances for configuring these features simultaneously.</span>

| **IB-FLEX Flavor Configuration** | **Total CPU** | **Total **<span style="color: #000000">**System **</span>**Memory in GB (With virtual DNS Cache Acceleration only)** | **Total **<span style="color: #000000">**System **</span>**Memory in GB (With virtual DNS Cache Acceleration and virtual Advanced DNS Protection Software)** | **Maximum Number of Concurrent Sessions Supported** | **Grid Master Capable** |
| --- | --- | --- | --- | --- | --- |
| <span style="color: #000000">Medium</span>  
<span style="color: #000000">recursive DNS (with acceleration)</span> | <span style="color: #000000">16</span> | <span style="color: #000000">64</span> | <span style="color: #000000">64</span> | <span style="color: #000000">For vDCA only: 150,000</span><br><span style="color: #000000">For vADP only: 60,000</span><br><span style="color: #000000">For vDCA and vADP: 150,000</span> | <span style="color: #000000">No</span> |
| <span style="color: #000000">Medium-Large</span>  
<span style="color: #000000">recursive DNS (with acceleration)</span> | <span style="color: #000000">16</span> | <span style="color: #000000">86</span> | <span style="color: #000000">86</span> | <span style="color: #000000">For vDCA only: 150,000</span><br><span style="color: #000000">For vADP only: 60,000</span><br><span style="color: #000000">For vDCA and vADP: 150,000</span> | <span style="color: #000000">No</span> |
| <span style="color: #000000">Large</span>  
<span style="color: #000000">recursive DNS (with acceleration)</span> | <span style="color: #000000">26</span> | <span style="color: #000000">100</span> | <span style="color: #000000">100</span> | <span style="color: #000000">For vDCA only: 240,000</span><br><span style="color: #000000">For vADP only: 80,000</span><br><span style="color: #000000">For vDCA and vADP: 240,000</span> | <span style="color: #000000">No</span> |

> ⚠️ **Note**
> ⚠️ 
> ⚠️ When a NIOS appliance does not have the required base memory configuration, if you try to enable and run DNS over TLS, DNS over HTTPS, and Parental Control features simultaneously, all of these features will be disabled.

# <span style="color: #000000">Supported Cipher Suites</span>

<span style="color: #1d1c1d">From NIOS 8.5.3 onwards, the DNS over TLS and DNS over HTTPS features support only TLS version 1.2 and TLS version 1.3. </span><span style="color: #000000">The cipher suite order preference is configured to improve the throughput in DNS over TLS and DNS over HTTPS communication.</span>

<span style="color: #000000">Cipher suites supported for TLS 1.2 are as follows:</span>

- <span style="color: #000000">ECDHE-ECDSA-CHACHA20-POLY1305</span>
- <span style="color: #000000">ECDHE-RSA-CHACHA20-POLY1305</span>
- <span style="color: #000000">ECDHE-ECDSA-AES128-GCM-SHA256</span>
- <span style="color: #000000">ECDHE-ECDSA-AES256-GCM-SHA384</span>
- <span style="color: #000000">ECDHE-ECDSA-AES128-SHA256</span>
- <span style="color: #000000">ECDHE-ECDSA-AES256-SHA384</span>
- <span style="color: #000000">ECDHE-RSA-AES128-GCM-SHA256</span>
- <span style="color: #000000">ECDHE-RSA-AES256-GCM-SHA384</span>
- <span style="color: #000000">ECDHE-RSA-AES128-SHA256</span>
- <span style="color: #000000">ECDHE-RSA-AES256-SHA384</span>
- <span style="color: #000000">DHE-RSA-AES128-GCM-SHA256</span>
- <span style="color: #000000">DHE-RSA-AES256-GCM-SHA384</span>
- <span style="color: #000000">DHE-RSA-AES128-SHA</span>
- <span style="color: #000000">DHE-RSA-AES256-SHA</span>
- <span style="color: #000000">DHE-RSA-AES128-SHA256</span>
- <span style="color: #000000">DHE-RSA-AES256-SHA384</span>

<span style="color: #000000">Cipher suites supported for TLS 1.3 are as follows:</span>

- <span style="color: #000000">TLS_CHACHA20_POLY1305_SHA256</span>
- <span style="color: #000000">TLS_AES_128_GCM_SHA256</span>
- <span style="color: #000000">TLS_AES_128_CCM_SHA256</span>
- <span style="color: #000000">TLS_AES_128_CCM_8_SHA256</span>
- <span style="color: #000000">TLS_AES_256_GCM_SHA384</span>

# Limitations and Recommendations for DNS over TLS and DNS over HTTPS

<span style="color: #000000">Consider the following limitations and recommendations when you enable the DNS over TLS and/or the DNS over HTTPS features:</span>

- <span style="color: #000000">If an appliance configured with DNS over TLS or DNS over HTTPS has both vDCA and vADP running, the configuration is set to the DCA-first mode.</span>
- <span style="color: #000000">TSIG queries for which responses are larger than the max EDNS/UDP buffer size are not supported.</span>
- <span style="color: #000000">DNS queries coming with EDNS padding over port 53 are dropped.</span>
- <span style="color: #000000">DNS over TLS and DNS over HTTPS features are not supported on unbound-based DNS servers.</span>
- <span style="color: #000000">When DNS over TLS or DNS over HTTPS is enabled, queries decrypted at DNS over TLS or DNS over HTTPS that do not receive a response from the vDCA cache are forwarded to the recursive DNS engine over UDP. Therefore, rules added for TCP requests over TLS or HTTPS may not be honored. Infoblox recommends that you add the corresponding UDP-specific rules instead of only the TCP request rules.</span>
- <span style="color: #000000">For NIOS 8.5.2 only: Infoblox recommends that you manually set the maximum packet size of both the UDP buffer and the EDNS buffer to 4096 bytes. If the packet size exceeds 4096, packets are dropped by the DNS over TLS or the DNS over HTTPS server. For more information about setting buffer sizes, see </span>*[<span style="color: #000000">Configuring the EDNS0 Buffer Size and UDP Buffer Size</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35483175/Using+Extension+Mechanisms+for+DNS+EDNS0#UsingExtensionMechanismsforDNS(EDNS0)-ConfiguringtheEDNS0BufferSizeandUDPBufferSize)*<span style="color: #000000">.</span>
- <span style="color: #000000">DNS over TLS only:</span>
  - <span style="color: #000000">The TLS versions that are currently supported by NIOS are TLS 1.2 and TLS 1.3.</span>
  - <span style="color: #000000">DNS over TLS supports queries and responses from both DNS and DNS Cache Acceleration services.</span>
  - <span style="color: #000000">DNS over TLS is not supported for recursive queries when performing upstream lookups.</span>
  - <span style="color: #000000">DNS zone transfer requests over DNS over TLS are not supported.</span>
  - <span style="color: #000000">For DNS over TLS clients that use systemd-resolved service, the Subject Alternative Name (SAN) must point to the IP address of the DNS service. By default, the self-signed certificates issued to Infoblox members do not meet this requirement. Therefore, for Infoblox to support systemd-resolved, you must install certificates that include SAN IP address from a trusted certificate authority.</span>
- <span style="color: #000000">DNS over HTTPS only:</span>
  - <span style="color: #000000">DNS over HTTPS is supported on the HTTP/2 protocol.</span>
  - <span style="color: #000000">DNS over HTTPS is supported only if the NIOS appliance has an MGMT interface set up. The DNS over HTTPS module listens on port 443 for interfaces other than MGMT and any incoming UI request to the MGMT interface is bypassed directly to the host.</span>
  - <span style="color: #000000">When DNS over HTTPS is enabled on a member, HTTP redirection from the member to its Grid Master is disabled.</span>

# DNS over TLS

<span style="color: #000000">NIOS appliances that support DNS Cache Acceleration or Advanced DNS Protection Software, include the DNS over TLS capability that helps increase DNS security and privacy. When you enable the DNS over TLS feature, DNS traffic is encrypted through the TLS protocol to prevent eavesdropping and tampering of DNS data. This feature is supported on both recursive and authoritative DNS servers only through port 853. It is available only for Grid members and for standalone systems. It supports the processing of multiple DNS queries/responses over a single TLS session.</span>

<span style="color: #000000">You can configure and run the DNS over TLS service on a member only when the following prerequisites are met:</span>

- <span style="color: #000000">Either the accelerated DNS Cache Acceleration (vDCA) or the Advanced DNS Protection Software (vADP) service is enabled.</span>
- The memory required to support the DNS over TLS feature is available. For more information, see the *<span style="color: #000000">Base Configuration Requirements</span>*<span style="color: #000000"> section.</span>

## Configuring DNS over TLS

<span style="color: #000000">To configure the DNS over TLS feature, complete the following steps:</span>

1. **<span style="color: #000000">Grid member</span>**<span style="color: #000000">: On the </span>**<span style="color: #000000">Data Management </span>**<span style="color: #000000">tab, click the </span>**<span style="color: #000000">DNS</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Members</span>**<span style="color: #000000"> tab, select the </span>*<span style="color: #000000">member</span>*<span style="color: #000000"> checkbox, and then click the Edit icon.</span>  
**<span style="color: #000000">Standalone system</span>**<span style="color: #000000">: On the </span>**<span style="color: #000000">Data Management</span>**<span style="color: #000000"> tab, click the </span>**<span style="color: #000000">DNS</span>**<span style="color: #000000"> tab, expand the Toolbar, and then click </span>**<span style="color: #000000">System DNS Properties</span>**<span style="color: #000000">.</span>
2. <span style="color: #000000">In the </span>*<span style="color: #000000">Member</span>*<span style="color: #000000"> </span>*<span style="color: #000000">DNS</span>*<span style="color: #000000"> </span>*<span style="color: #000000">Properties</span>*<span style="color: #000000"> editor/</span>*<span style="color: #000000">System DNS Properties</span>*<span style="color: #000000"> editor, click </span>**<span style="color: #000000">Toggle Advanced Mode</span>**<span style="color: #000000"> if the editor is in basic mode.</span>
3. <span style="color: #000000">On the </span>**<span style="color: #000000">Queries</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Advanced</span>**<span style="color: #000000"> tab, select the </span>**<span style="color: #000000">Enable DoT Service</span>**<span style="color: #000000"> checkbox to enable the DNS over TLS feature.</span>  
<span style="color: #000000">Note that </span><span style="color: #000000">the options for DNS over TLS feature are displayed only if the appliance has the memory footprint that is required to support the feature and has the DNS Cache Acceleration or Advanced DNS Protection Software license installed. For more information, see</span><span style="color: #000000"> </span><span style="color: #000000">the </span>*<span style="color: #000000">Base Configuration Requirements</span>*<span style="color: #000000"> section.</span>
4. <span style="color: #000000">In the </span>**<span style="color: #000000">Maximum Session Timeout</span>**<span style="color: #000000"> field, specify the maximum time in seconds a session can remain idle before it times out and closes. The default value is 60 seconds.</span>  
<span style="color: #000000">If your DNS forwarders are located at different geographical locations or if the network latency is high, you may observe session timeouts. If so, Infoblox recommends that you set the </span>**<span style="color: #000000">Maximum Session Timeout</span>**<span style="color: #000000"> to more than 60 seconds. Increasing the session duration may impact concurrent open sessions.</span>
5. <span style="color: #000000">Save the configuration.</span>
6. <span style="color: #000000">As prompted, manually </span>reboot <span style="color: #000000">the member to enable the DNS over TLS feature.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">The DNS over TLS feature will not take effect until you </span>reboot <span style="color: #000000">the member or the standalone system and ensure that either the </span><span style="color: #000000">DNS Cache Acceleration</span><span style="color: #000000"> or </span><span style="color: #000000">Advanced DNS Protection Software</span><span style="color: #000000"> service is running after the </span>reboot<span style="color: #000000">.</span>

## CLI Support for DNS over TLS

<span style="color: #000000">You can view the status of the DNS over TLS service, configuration, and details of active sessions using the following commands:</span>

- [<span style="color: #000000">*show dns-over-tls-status*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35479836)
- [<span style="color: #000000">*show dns-over-tls-config*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35414993)
- [<span style="color: #000000">*show dns-over-tls-stats*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35479930)

# DNS over HTTPS

<span style="color: #000000">NIOS appliances that support DNS Cache Acceleration or Advanced DNS Protection Software, include the DNS over HTTPS capability that helps increase DNS security and privacy. When you enable the DNS over HTTPS feature, DNS traffic is encrypted through the HTTPS protocol to prevent eavesdropping and tampering of DNS data. This feature is supported on both recursive and authoritative DNS servers only through port 443. It is available only for Grid members and standalone systems. The feature supports the processing of multiple DNS queries/responses over a single TCP session.</span>

<span style="color: #000000">You can configure and run the DNS over HTTPS service on a NIOS appliance only when the following prerequisites are met:</span>

- <span style="color: #000000">An MGMT interface is set up.</span>
- <span style="color: #000000">The memory required to support the DNS over HTTPS feature is available. For more information, see </span>the *<span style="color: #000000">Base Configuration Requirements</span>*<span style="color: #000000"> section.</span>
- <span style="color: #000000">Either the accelerated DNS Cache Acceleration (vDCA) or the Advanced DNS Protection Software (vADP) service is enabled</span><span style="color: #000000">.</span>

## Configuring DNS over HTTPS

<span style="color: #000000">To</span><span style="color: #000000"> configure the DNS over HTTPS feature, complete the following steps:</span>

1. **<span style="color: #000000">Grid member</span>**<span style="color: #000000">: On the </span>**<span style="color: #000000">Data Management</span>**<span style="color: #000000"> tab, click the </span>**<span style="color: #000000">DNS</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Members</span>**<span style="color: #000000"> tab, select the </span>*<span style="color: #000000">member</span>*<span style="color: #000000"> checkbox, and then click the Edit icon.</span>  
**<span style="color: #000000">Standalone system</span>**<span style="color: #000000">: On the </span>**<span style="color: #000000">Data Management</span>**<span style="color: #000000"> tab, click the </span>**<span style="color: #000000">DNS</span>**<span style="color: #000000"> tab, expand the Toolbar, and then click </span>**<span style="color: #000000">System DNS Properties</span>**<span style="color: #000000">.</span>
2. <span style="color: #000000">In the </span>*<span style="color: #000000">Member</span>*<span style="color: #000000"> </span>*<span style="color: #000000">DNS</span>*<span style="color: #000000"> </span>*<span style="color: #000000">Properties</span>*<span style="color: #000000"> editor/</span>*<span style="color: #000000">System DNS Properties</span>*<span style="color: #000000"> editor, click </span>**<span style="color: #000000">Toggle Advanced Mode</span>**<span style="color: #000000"> if the editor is in basic mode.</span>
3. <span style="color: #000000">On the </span>**<span style="color: #000000">Queries</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Advanced</span>**<span style="color: #000000"> tab, select the </span>**<span style="color: #000000">Enable DoH Service</span>**<span style="color: #000000"> checkbox to enable the DNS over HTTPS feature.</span>  
<span style="color: #000000">Note that the</span><span style="color: #000000"> options for DNS over HTTPS feature are displayed only if the appliance has the memory footprint that is required to support the feature and has the DNS Cache Acceleration or Advanced DNS Protection Software license installed. For more information, </span><span style="color: #000000">see the </span><span style="color: #000000">the </span>*<span style="color: #000000">Base Configuration Requirements</span>*<span style="color: #000000"> section.</span>
4. <span style="color: #000000">In the </span>**<span style="color: #000000">Maximum Session Timeout</span>**<span style="color: #000000"> field, specify the maximum time in seconds a session can remain idle before it times out and closes. The default value is 10 seconds.</span>  
<span style="color: #000000">If your DNS forwarders are located at different geographical locations or if the network latency is high, you may observe session timeouts. If so, Infoblox recommends that you set the </span>**<span style="color: #000000">Maximum Session Timeout</span>**<span style="color: #000000"> to more than 10 seconds. Increasing the session duration may impact concurrent open sessions.</span>
5. <span style="color: #000000">Save the configuration.</span>
6. As prompted, manually reboot the member to enable the DNS over HTTPS feature.

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">The DNS over HTTPS feature will not take effect unless you </span>reboot <span style="color: #000000">the member </span><span style="color: #000000">or the standalone system </span><span style="color: #000000">and ensure that either the </span><span style="color: #000000">DNS Cache Acceleration or Advanced DNS Protection Software</span><span style="color: #000000"> service is running after the reboot.</span>

### <span style="color: #000000">Configuring DNS over HTTPS in Firefox</span>

<span style="color: #000000">If you are using the developer version of the Firefox browser to initiate DNS queries, you must configure additional settings in the browser to enable the DNS over HTTPS support. Complete the following steps in Firefox to enable DNS over HTTPS and upload certificates:</span>

1. <span style="color: #000000">In the </span>**<span style="color: #000000">Network Settings</span>**<span style="color: #000000"> section, click </span>**<span style="color: #000000">Settings</span>**<span style="color: #000000"> and complete the following steps to set the Grid IP address as the custom DNS over HTTPS server:</span>
  1. <span style="color: #000000">In the </span>*<span style="color: #000000">Connection Settings</span>*<span style="color: #000000"> dialog box select the </span>**<span style="color: #000000">Enable DNS over HTTPS</span>**<span style="color: #000000"> checkbox.</span>
  2. <span style="color: #000000">From the </span>**<span style="color: #000000">Use Provider</span>**<span style="color: #000000"> drop-down list, choose </span>**<span style="color: #000000">Custom</span>**<span style="color: #000000">.</span>
  3. <span style="color: #000000">In the </span>**<span style="color: #000000">Custom</span>**<span style="color: #000000"> field, enter the Grid IP address in the format:</span>  
<span style="color: #000000">https://<</span>*<span style="color: #000000">dns-server</span>*<span style="color: #000000">>/dns-query</span>
2. <span style="color: #000000">Set the network.trr.mode preference in the configuration editor as follows:</span>
  1. <span style="color: #000000">Enter </span>**<span style="color: #000000">about:config</span>**<span style="color: #000000"> in the Firefox address bar.</span>
  2. <span style="color: #000000">Click </span>**<span style="color: #000000">Accept the Risk and Continue</span>**<span style="color: #000000"> to open the configuration editor.</span>
  3. <span style="color: #000000">Search for </span>**<span style="color: #000000">network.trr.mode</span>**<span style="color: #000000">.</span>
  4. <span style="color: #000000">Click the Edit icon and set the value to </span>**<span style="color: #000000">3</span>**<span style="color: #000000">.</span>
3. <span style="color: #000000">If you are using a self-signed certificate, complete the following:</span>
  1. <span style="color: #000000">From the address bar, open https://<</span>*<span style="color: #000000">doh_server_IP</span>*<span style="color: #000000">>. </span>
  2. <span style="color: #000000">Accept </span><span style="color: #000000">the certificate.</span>
4. <span style="color: #000000">If you are using a CA certificate, complete the following:</span>
  1. <span style="color: #000000">Go to </span>**<span style="color: #000000">Preferences</span>**<span style="color: #000000">/</span>**<span style="color: #000000">Options</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Privacy and Security</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">View Certificates</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Authorities</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Import</span>**<span style="color: #000000">.</span>
  2. <span style="color: #000000">Choose the certificate.</span>
  3. <span style="color: #000000">When prompted, select the </span>**<span style="color: #000000">Trust this CA to identify websites</span>**<span style="color: #000000"> checkbox, and restart the browser.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">For a member with the DNS Cache Acceleration service running and the DNS over HTTPS feature enabled, if you use the developer version of the Firefox browser (configured for DNS over HTTPS support) to initiate DNS queries, you must set the </span>**<span style="color: #000000">network.trr.disable-ECS</span>**<span style="color: #000000"> preference in the configuration editor (about:config) to </span>**<span style="color: #000000">false</span>**<span style="color: #000000"> for DNS data to be cached. DNS caching does not work if </span>**<span style="color: #000000">network.trr.disable-ECS</span>**<span style="color: #000000"> is set to </span>**<span style="color: #000000">true</span>**<span style="color: #000000">.</span>

## <span style="color: #000000">CLI Support for DNS over HTTPS</span>

<span style="color: #000000">You can view the status of the DNS over HTTPS service, configuration, and details of active sessions using the following commands:</span>

- [<span style="color: #000000">*show doh-status*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35382931)
- [<span style="color: #000000">*show doh-config*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35383107)
- [<span style="color: #000000">*show doh-stats*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35415004)