Citrix SD-WAN

Domain name system

Domain Name System (DNS) translates human readable domain names to machine-readable IP addresses, and vice versa. Citrix SD-WAN provides the following DNS features:

  • DNS Proxy
  • DNS Transparent Forwarding

You can configure a DNS proxy or DNS transparent forwarding through Citrix SD-WAN Orchestrator service using the following types of DNS service:

  • Static DNS service: Allows you to configure the static IPv4 DNS server IP addresses. You can create Internal, ISP, google, or any other open source DNS service. Static DNS service can be configured at global and site level.

  • Dynamic DNS service: Allows you to configure the dynamic IPv4 DNS server IP addresses. Dynamic DNS service can be configured at site level only. Only one dynamic DNS service is permitted per site.

  • StaticV6 DNS service: Allows you to configure the static IPv6 DNS server IP addresses. You can create Internal, ISP, google, or any other open source DNS service. StaticV6 DNS service can be configured at global and site level.

  • DynamicV6 DNS service: Allows you to configure the dynamic IPv6 DNS server IP addresses. DynamicV6 DNS service can be configured at site level only. Only one dynamic DNS service is permitted per site.

DNS proxy

You can configure a proxy with multiple forwarders that helps steering DNS requests based on application domain names. DNS forwarding works for the requests that are received through UDP connections. For information on how to configure DNS proxy through SD-WAN Orchestrator service, see DNS proxy.

DNS transparent forwarder

Citrix SD-WAN can be configured as a transparent DNS forwarder. In this mode, SD-WAN can intercept DNS requests that are not destined to its IP address and forward them to the specified DNS service. Only the DNS requests coming from local service on trusted interfaces are intercepted. If the DNS requests match any applications in the DNS forwarder list, then it is forwarded to the configured DNS service. DNS forwarding is supported only for requests coming over UDP connections. For information on how to configure DNS tranparent forwarder through SD-WAN Orchestrator service, see DNS tranparent forwarders.

Monitoring

To view Proxy statistics and Transparent forwarder statistics, navigate to Monitoring > DNS. You can view the application name, DNS service name, DNS service status, and the number of hits to the DNS service.

Proxy Statistics

Proxy statistics

Transparent Forwarder Statistics

Transparent forwarder statistics

Domain name system