This section describes the application scenario of the FW working as a DNS proxy.
After the DNS proxy function is enabled, the device can forward DNS request and response packets between the internal DNS clients and external DNS server. When the DNS server address changes, you only need to configure the DNS proxy, not all the DNS clients on the LAN. Therefore, the DNS proxy simplifies network management.
Figure 1 shows the typical networking in which FW serves as a DNS Proxy.
In the network environment shown in Figure 1, FW works as the egress gateway of the branch. In the headquarters, the network is configured with DNS server and FTP server, and the mappings between the domain names and the IP address of the FTP server is recorded on the DNS server. In addition, the routes between both the servers and the FW are reachable. In order to realize that users of the branch to access to the FTP server of the headquarters by domain name, the FW can be configured to forward the request and response packets between the user hosts of the branch and the DNS server of the headquarters as a DNS proxy.