As a DNS proxy server, NetScaler can function as a proxy for either a single DNS server or a group of DNS servers. The flow of requests and responses is illustrated in the following sample topology diagram.
Figure 1. NetScaler as DNS proxy
By default, NetScaler caches responses from DNS name servers. When the appliance receives a DNS query, it checks for the queried domain in its cache. If the address for the queried domain is present in its cache, the NetScaler returns the corresponding address to the client. Otherwise, it forwards the query to a DNS name server that checks for the availability of the address and returns it to the NetScaler. The NetScaler then returns the address to the client.
For requests for a domain that has been cached earlier, the NetScaler serves the Address record of the domain from the cache without querying the configured DNS server.
For the DOT request for a domain, if the cached information is not encrypted, NetScaler® forwards the query to a DNS name server that checks for the availability of the address and returns it to NetScaler. NetScaler encrypts the address and response to the client. It also caches the records with a secure option. For the UDP or TCP request for a domain that has a secure option enabled, NetScaler serves the address record of the domain from the cache without querying the configured DNS server.
The appliance discards a record stored in its cache when the time-to-live (TTL) value of the record reaches the configured value. A client that requests an expired record has to wait until the NetScaler retrieves the record from the server and updates its cache. To avoid this delay, the NetScaler proactively updates the cache by retrieving the record from the server before the record expires.
The following table lists sample names and the values of the entities that need to be configured on the NetScaler.
Table 1. Example of DNS Proxy Entity Configuration
| Entity type |
Name |
IP address |
Type |
Port |
| LB virtual server |
Vserver-DNS-1 |
10.102.29.40 |
DNS |
53 |
| Services |
Service-DNS-1 |
10.102.29.50 |
DNS |
53 |
| Services |
Service-DNS-2 |
10.102.29.51 |
DNS |
53 |
The following diagram shows the entities of a DNS Proxy and the values of the parameters to be configured on the NetScaler.
Figure 2. DNS Proxy Entity Model
To configure the DNS proxy feature, you need to know how to configure load balancing services and virtual servers.