The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure the DNS server details

Prev Next

You must configure the DNS server details in the Manager, if you have Firewall, QoS, or Quarantine Zone rules that use Host DNS Name rule object. The Sensors use these DNS server details to resolve the Host DNS Name rule objects to IP addresses. This also applies to rules using Network Group rule objects, which in turn use a Host DNS Name rule object.

In addition to what is mentioned above, NS-series Sensors use the DNS server details to resolve the host name of the syslog server used for Firewall or Quarantine. You can configure the Sensor to forward the details of matched Firewall or Quarantine Zone rules to a syslog server. As part of this configuration, you define the syslog-server details in the Manager. If you provide the host name of the syslog server, then the Sensor uses the DNS server to resolve the syslog server's host name.

Important

The Sensor uses only UDP and never falls back to TCP for DNS queries even if the DNS server forces for TCP.

You can configure the DNS server details at a domain level or at a device level. The DNS server at the admin domain, by default, applies to the following:

  • All the corresponding child domains

  • All the Sensors in this domain. This includes any interfaces delegated to other domains.

  • All the Sensors in the corresponding child domains

If required, you can override the DNS server details at a child admin domain level and also at each Sensor level.

  1. To configure the DNS server details for an admin domain:

    1. Click the Devices tab.

    2. Select the domain from the Domain drop-down list.

    3. Select Global → Common Device Settings → Name Resolution.

      DNS window
      DNS window


  2. To configure the DNS server details for a Sensor:

    1. Click the Devices tab.

    2. Select the domain from the Domain drop-down list.

    3. On the left pane, click the Devices tab.

    4. Select the device from the Device drop-down list.

    5. Select Setup → Name Resolution.

    6. Deselect Inherit Settings? to override the settings of the parent domain.

  3. Enter the DNS information in the corresponding fields.

    Option

    Definition

    Enable Name Resolution?

    Select to display the fields in the Name Resolution page.

    Note

    If you deselect this field and click Save, the DNS details that you had saved earlier is lost.

    DNS Suffixes

    You can enter multiple values separated by a space. The Sensor uses these suffixes, in the same order, to resolve non-qualified DNS host names in your Firewall rules. Consider that the DNS host name in your Firewall rule is “host1” and the DNS suffixes are “mycompany.com” and “mycompany.org”. To resolve this host name, the Sensor first tries host1.mycompany.com. If this fails, it tries host1.mycompany.org.

    Primary DNS Server

    Enter the IPv4 or IPv6 address of the DNS server that the Sensor must contact first.

    Secondary DNS Server

    Optionally, enter the IPv4 or IPv6 address of a secondary DNS server. If the primary DNS server is unreachable, the Sensor communicates with the secondary DNS server.

    Refresh Interval

    If you are configuring the details for an admin domain, then enter a value between 24 and 9999. Though this field is applicable only to NTBA, you must enter a value when configuring the details for an admin domain.

    Test Connection

    Click this button to check the connectivity to the DNS Server. The status of the connectivity test is displayed in the Name Resolution page.

    Save

    Saves the DNS server details in the Manager database.

    Tip

    To resolve the Host DNS Name rule objects, the Sensor management port must be able to connect to Save the specified DNS servers. So, to be sure, ping the DNS servers from the Sensor CLI.

  4. Perform a configuration update to the relevant Sensors.

    Note

    If the Sensor is unable to communicate with a DNS server, a fault of severity Warning is displayed on the Faults tab in Logs page.