Glossary

DNS

Domain Name System

What is DNS

DNS (Domain Name System) is one of the core services underpinning the Internet: a distributed database that maps human-readable domain names to the IP addresses computers actually use to find each other. Instead of remembering a numeric address for every site or service, users type a name — and DNS resolves it into the address a device needs to actually make the connection.

That mapping is organized through a hierarchical naming architecture, which is what lets DNS manage and resolve domain names consistently across the entire Internet rather than requiring every network to maintain its own private naming scheme. Compared to older host-file-based resolution — where every device kept its own local list of name-to-address mappings — DNS is dramatically more efficient, reliable, and scalable, combining an efficient resolution mechanism, a distributed system architecture, caching for performance, and redundant backup servers into a system that gives users a seamless, "it just works" experience getting online.

How DNS Works

On a network device, DNS support generally starts with DNS relay: rather than the device running its own full recursive resolver, it forwards DNS queries from downstream clients to one or more configured upstream DNS servers — a straightforward, low-overhead way to give a whole network access to name resolution without deploying dedicated DNS infrastructure.

Beyond basic relay, DNS information can be organized into DNS query groups — named collections of specific domain names (like www.example.com) that a device is configured to recognize and track. Rather than treating DNS purely as a pass-through resolution service, grouping domains this way turns domain-name awareness into something the rest of the device's configuration — like security policy — can reference directly.

That's exactly what DNS ACL does: standard access-list rules typically match traffic by source or destination IP address, but a DNS ACL rule can instead match by source or destination DNS group — filtering traffic based on the domain name a client resolved, rather than the resulting IP address. Because IP-based and DNS-group-based matching represent traffic identification in fundamentally different ways, a single ACL rule can't combine both — a rule matches on IP address or on DNS group, not a mix of the two. This matters in situations where an IP-based rule would be fragile: a domain's underlying IP address can change (a CDN reassigning addresses, a service migrating hosts), but the domain name itself — and therefore the DNS-group match — stays valid.

Why DNS is Beneficial

  • Makes the Internet usable by humans: Domain names are memorable in a way raw IP addresses never could be, and DNS is the translation layer that makes that convenience possible without sacrificing how machines actually route traffic.

  • Scales through hierarchy and caching: Distributed, hierarchical resolution combined with caching keeps DNS fast and resilient even at Internet scale, rather than depending on a single central lookup service.

  • DNS relay simplifies network deployment: A device doesn't need to run its own authoritative or recursive DNS infrastructure to give downstream clients working name resolution — relay to an upstream server is enough.

  • DNS-aware policy is more resilient than IP-only policy: Filtering or controlling traffic by domain name survives the routine IP address changes that would silently break an equivalent IP-based rule.

  • Redundancy keeps resolution available: Backup DNS servers and caching mean name resolution keeps working even when a single upstream server has a problem.

At Asteraix

What We Can Do at Asteraix

AsterNOS implements DNS relay, domain-name query groups, and DNS-aware ACL matching, configurable directly through the CLI — turning DNS from a pass-through service into a building block for network policy.

  • Simple DNS relay setup: dns relay enable combined with dns server <A.B.C.D> (for example, 8.8.8.8) stands up working DNS forwarding for downstream clients in two commands, with show dns server available to confirm the configured upstream server.

  • Named, reusable domain groups: dns query-group <name> creates a named group, and repeated query <hostname> commands (hostnames up to 64 bytes) populate it with specific domains to track — a group defined once that can then be referenced anywhere DNS-aware matching is needed.

  • Domain-based ACL enforcement: Inside an L3 or L3v6 ACL rule, {src-dns-group|dst-dns-group} <name> matches traffic against a configured domain group instead of an IP address — implementing exactly the domain-name-based firewall policy that IP-only ACLs can't express, with AsterNOS's documentation explicit that DNS-group and IP-address matching can't be combined in the same rule.

  • Documented, real-world policy example: AsterNOS's own configuration example walks through a complete enterprise firewall scenario — enabling DNS relay, defining a query group covering specific domains, and building an ACL rule that denies intranet access to traffic sourced from that domain group, then binding the ACL to an interface — giving operators a concrete reference for building their own domain-based access policy.