The Domain Name System (DNS) is a system which translate domain names to IP Addresses and vice versa. The Sophos XG Firewall (SF) supports both static and dynamic DNS for resolving domain names.
Static DNS Host Entry: Sophos supports static DNS host entry where the SF acts as a DNS Server that provides the requesting client with the "A" records to resolve the requested URL. SF supports multiple DNS Host Entries for a single website hosted behind the SF.
Suppose there is a website www.example.com whose resolved address is 10.10.10.1.
When a user tries to access the website www.example.com, the following steps will take place in order to resolve this domain name into an IP address:
Every time a client tries to access a website using its domain name, these steps will take place in order to resolve a domain name into its IP address.
SF can use a Static DNS instead. By adding a static DNS entry for a particular domain name, SF resolves the domain name itself and the request will not be forwarded to a DNS server.
The following sections are covered:
This article describe the steps on how to configure a Static DNS host entry for a website www.example.com in SF.
The new steps that will be followed when any user tries to access the website www.example.com with the help of a static DNS host entry are the following:
You must be logged in to the Web Admin Console as an administrator with read-write permission for the relevant feature(s).
Note: You can find resolved addresses for any domain name using the CLI of the SF.
The following steps can be used to find the resolved address for any domain name:
dnslookup host <domain name>
The configuration above will create a DNS host entry for a domain name.
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.