Infoblox’s global team of threat hunters uncovers a DNS operation with the ability to bypass traditional security measures and control the Great Firewall of China. Read about “Muddling Meerkat” and the many other threat actors discovered by Infoblox Threat Intel here.



MS-DNS Integration with Domain and Sub-domains

New Member
Posts: 1
1051     0

We are planning out a project for making our Infoblox Appliances our Front End DNS Servers for our Microsoft (mostly) Domain Environment. Our plan is to continue to store the DNS Zones in Active Directory.


One of the questions that has come up is we have 3 Domains in a single forest: and We are trying to get an understanding, what is the best approach for the Sub Domains. In MS-DNS, these zones have been created in the Root ( Zone as Delegated Zones (DNS Requests are forwarded to the Domain Controllers of that particular Domain). However, if all clients are being pointed to Infoblox, I am thinking it makes more sense for these to be Sub-zones within the Root Zone as there really isn't any where to forward the request to if the Zone is also hosted on Infoblox. Does any one have experience with this or any suggestions?

Re: MS-DNS Integration with Domain and Sub-domains

Posts: 105
1051     0



From your description i can say that you are going to use zone transfer from AD to Infoblox. From the question you have 3 domains which are:


- (as the root)

- (configured as delegation)

- (configured as delegation)


If we look into the zone file for the subzone it should be IN NS IN NS IN A IN A


In zone transfer this record will be included in xfr (zone transfer). It means that infoblox will receive the copy of entire zones include with the delegation NS record.


so when the client tries to query a domain then infoblox will forward the query and also with will forward to


One thing you need to make sure in infoblox when you configure the zone is the "Don't use forwarders to resolve queries in subzones" settings is checked. If this zone is not checked then the query will be forwarded to the global forwarder instead of the delegated NS ip.

Showing results for 
Search instead for 
Did you mean: 

Recommended for You