FMC and selective DNS queries

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-12-2020 11:30 AM
Is there a way to combine FMC DNS SI lists by the domain name feature and a particular DNS query type? Let's say I want to avoid type A DNS queries but I let type AAAA queries to go out for domain A, but I want both A and AAAA allowed for domain B. Or I do not want type LOC queries to be sent out anywhere. Is it possible?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-12-2020 06:35 PM
I don't think DNS SI can give you this. Its lookup at domain name in the
query (A or AAAA) and performs the analysis but you can't tweak for
specific record types.
***** please remember to rate useful posts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-13-2020 05:26 AM
Hi al Baqari.
Yep, DNS policies (via SI) is an "all inclusive" for the domain, but maybe there was anther place that I was not aware we could do DNS related policies.
It is a shame - another fine granular feature missing from FMC. Thanks, though.
