AZTCOFW / DOCUMENTATION
Configuring DNS over TLS
Configuration guides, troubleshooting and practical advice for AZTCOFW.
Articles
6 resultsCaveats
Clients can make their own connections to DNS over TLS servers, so block them on TCP/UDP ports 53 and 853 to ensure they only query the DNS Resolver ( Blocking External Client DNS Queries ). Redirecting DNS over TLS quer
Configure DNS Servers
First, configure the DNS servers on the firewall. Warning: When the firewall uses DNS over TLS, every DNS server used by the firewall must support DNS over TLS. Navigate to System > GeneralLocate the DNS Server Settings
Enable DNS over TLS for Forwarded Queries
Next, configure the DNS Resolver to use DNS over TLS for outgoing queries. Navigate to Services > DNS ResolverUncheck Enable DNSSEC Support Note: DNSSEC is not generally compatible with forwarding mode, with or without D
Enable DNS over TLS Server (optional)
The DNS Resolver can also act as a DNS over TLS server, though it does not affect outbound/forwarded queries, so this section is optional. Only enable this feature if local clients must talk to the DNS Resolver using DNS
Requirements
This feature is only supported by the DNS Resolver. If the firewall is currently using the DNS Forwarder , convert to the DNS Resolver before starting this procedure. Pick a DNS over TLS upstream provider, such as a priv
Testing DNS over TLS
There are several ways to validate that outbound queries are using DNS over TLS. Test via Diagnostics > DNS Lookup and ensure the result from 127.0.0.1 is correct. Check for states using port 853 going to the DNS servers