Deployment
Secure DNS is managed via the web interface.
To begin, you must first choose one of the following deployment options:
cloud
hybrid
With the cloud deployment, the BI.ZONE Secure DNS recursive resolver operates in the BI.ZONE cloud. Your DNS server forwards all DNS queries through this resolver. This limits the visibility of your private network IP addresses.
The cloud deployment option is shown in the figure below:

The hybrid deployment utilizes both the cloud and on-prem components of the Solution:
The BI.ZONE Secure DNS recursive resolver operates in the BI.ZONE cloud.
Secure DNS Client Node is deployed on-premises (we recommend at least two hosts). It is positioned between the endpoints (computers and servers) in your local area network and your private or public DNS servers.
This reduces the volume of DNS traffic from the recursive resolver to public servers and addresses the limited private IP visibility associated with the cloud deployment option.
The hybrid deployment option is shown in the figure below:

Limitations
With the cloud deployment, DNS queries from the organization's local area network source from the network's egress IP address, limiting the visibility of private IP addresses.
To remove this limitation, ensure your existing recursive DNS server (if present) supports DNS over TLS (DoT) or DNS over HTTPS (DoH) along with EDNS0 option 8.
To determine a suitable deployment option:
Complete the questionnaire provided by BI.ZONE.
Email the completed questionnaire to your BI.ZONE contact.
Based on your responses, BI.ZONE will recommend the best option for you.
Proceed with the steps for the chosen deployment model.