Updated on 2026-07-15 GMT+08:00

Configuring a DNS Server

Scenario

Domain Name System (DNS) servers convert domain names into IP addresses, providing basic support for delivering protection policies. CFW provides the following two configuration modes to meet different resolution requirements:

  • Default DNS server: The system provides a built-in default DNS server. You do not need to manually add an address. This mode is applicable to common public domain name resolution scenarios. You can select the default DNS server with one click for services that do not have special resolution requirements.
  • Custom DNS server: You can manually add a custom DNS address. This mode is applicable to scenarios where private DNS, enterprise-built DNS, or intranet domain name resolution is required. It can flexibly adapt to differentiated service requirements.

On the DNS server configuration page of CFW, you can view or change the default DNS server or custom DNS server.

Notes and Constraints

  • A maximum of two DNS servers can be customized.
  • If there are multiple firewall instances, the DNS resolution setting applies only to the firewall instance where this setting is configured.

Configuring a DNS Server

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation tree on the left, choose System Management > DNS Resolution.
  5. Select a configuration mode.

    • Default DNS server: Select the default server in Default DNS Server.
    • Custom DNS server: In Custom DNS Server, click Add, enter the IP address of the custom DNS server, and click Save.

      Currently, only two custom DNS servers can be added.

  6. Click Apply.

    If the current account has multiple firewalls, the DNS resolution setting only applies to the firewall where this setting is configured.

Follow-up Operations

After the DNS service is configured, you need to add protection rules. For details, see Access Control.