Preparing the infrastructure
If you are deploying Secure DNS in hybrid mode, you must prepare your infrastructure.
For high availability, use at least two Secure DNS Client Node hosts.
The preparation includes the following steps:
Submit to BI.ZONE a list of your private DNS servers and the private second-level domains they resolve.
If you have dedicated DNS servers that resolve specific domains within your second-level domain namespace, also provide their details to BI.ZONE.For example:
Ensure the Secure DNS Client Node virtual machines have network access to the Secure DNS cloud recursive resolvers via TCP ports 853 and 443.
Ensure the Secure DNS Client Node virtual machines have network access to the Secure DNS cloud infrastructure:
https://cloud.sdns.mss.bi.zone/(disable SSL Inspection on next-generation firewalls)https://provision.sdns.mss.bi.zone/(disable SSL Inspection on next-generation firewalls)https://gti.bi.zone/
If your security policies restrict direct access to the hosts listed in section 6, you can set up a connection via an HTTP proxy. To do this, follow these steps:
Ensure the Secure DNS Client Node virtual machines have network access to the HTTP Proxy.
Specify the proxy server's IP address and port when deploying Secure DNS Client Node from an archive or from a VMware virtual machine template.
Ensure your organization's local area network hosts have access to the Secure DNS Client Node virtual machines via TCP/UDP port 53.
If you are using cryptographic protocols for DNS queries (DoH and/or DoT) within your organization, you must ensure your local area network hosts have access to the Secure DNS Client Node virtual machines via TCP port 443 (DoH) and/or TCP port 853 (DoT).