Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

DNS group objects

Want to summarize with AI?

Log in

An overview of DNS group objects, including DNS, HTTP, SSH, NTP, logging, sysopt, and device association settings.


A DNS group defines a list of DNS servers and associated attributes. DNS servers resolve FQDNs, such as www.example.com, to IP addresses. You can configure different DNS group objects for management and data interfaces.


Create a DNS Group Object

Use the following procedure to create a new DNS group object in Security Cloud Control:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click > FTD > DNS Group.

4.

Enter an Object Name.

5.

(Optional) Add a description.

6.

Enter the IP address of a DNS server. You can add up to six DNS servers; click the Add DNS Server. If you want to remove a server address, click the delete icon.

Note

The list is in priority order: the first server in the list is always used, and subsequent servers are used only if a response is not received from the servers above it. Although you can add up to six servers, only the first 3 servers listed will be used for the management interface.

7.

Enter the Domain Search Name. This domain is added to hostnames that are not fully qualified; for example, serverA instead of serverA.example.com.

8.

Enter the number of Retries. The number of times, from 0 to 10, to retry the list of DNS servers when the system does not receive a response. The default is 2. This setting applies to DNS groups used on the data interfaces only.

9.

Enter the Timeout value. The number of seconds, from 1 to 30, to wait before trying the next DNS server. The default is 2 seconds. Each time the system retries the list of servers, this timeout doubles. This setting applies to DNS groups used on the data interfaces only.

10.

Click Add.


Edit a DNS Group Object

You can edit a DNS group object that was created in Security Cloud Control or in Firewall Device Manager. Use the following procedure to edit an existing DNS group object:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the Security Cloud Control navigation bar on the left, click Objects.

3.

Locate the DNS Group Object you want to edit by using object filters and search field.

4.

Select the object and click the edit icon in the Actions pane.

5.

Edit any of the following entries:

  • Object Name.

  • Description.

  • DNS Server. You can edit, add, or remove DNS servers from this list.

  • Domain Search Name.

  • Retries.

  • Timeout.

6.

Click Save.

7.

Preview and Deploy Configuration Changes for All Devices.


Delete a DNS Group Object

Use the following procedure to delete a DNS Group Object from Security Cloud Control:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Locate the DNS Group Object you want to edit by using object filters and search field.

4.

Select the object and click the Remove icon .

5.

Confirm you want to delete the DNS group object and click Ok.

6.

Preview and Deploy Configuration Changes for All Devices.


Add a DNS Group Object as an FDM-Managed DNS Server

You can add a DNS group object as the preferred DNS Group for either the Data Interface or the Management Interface.