Configure DNS when an ISP tenant uses DNS proxy.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by PAN-OS or Panorama)
| |
In this use case, multiple tenants (ISP subscribers)
are defined on the firewall and each tenant is allocated a separate
virtual system (vsys) and virtual router in order to segment its
services and administrative domains. The following figure illustrates
several virtual systems within a firewall.
Each tenant
has its own server profiles for Security policy rules, reporting,
and management services (such as email, Kerberos, SNMP, syslog,
and more) defined in its own networks.
For the DNS resolutions
initiated by these services, each virtual system is configured with
its own
DNS Proxy Object to
allow each tenant to customize how DNS resolution is handled within
its virtual system. Any service with a
Location will
use the DNS Proxy object configured for the virtual system to determine
the primary (or secondary) DNS server to resolve FQDNs, as illustrated
in the following figure.