Edge for networking

Intelligently direct DNS traffic and tame conditional forwarding rules

BlueCat Edge for networking datasheet header with logo, page title, and introductory marketing text
Key takeawaysKey takeaways are generated with AI assistance. Because automated summaries can occasionally contain errors or miss important context, always refer to the full blog post for complete information.

The article introduces BlueCat Edge, a first-hop DNS layer that gives network teams visibility, control, and detection for DNS traffic in hybrid and multicloud environments to reduce latency and resolve DNS bottlenecks. By using intelligent forwarding via service points, Edge automates conditional forwarding, applies security policies, and centralizes logging to improve performance, resilience, and compliance across distributed networks. Edge service points can be deployed on BlueCat DNS/DHCP Servers, virtual platforms, select Cisco hardware, and major clouds to provide highly available, fault-tolerant DNS resolution with zero-touch deployment and WACG 2.2 AA accessibility compliance.

How does BlueCat Edge reduce DNS resolution latency in hybrid and multicloud environments?

BlueCat Edge reduces DNS resolution latency by acting as the first hop for DNS queries and using intelligent forwarding via service points. Rather than maintaining manual conditional forwarding rules across multiple authoritative servers, Edge uses namespaces and match or exception domain lists to route queries to the most appropriate resolution path. This provides multiple optimized resolution paths, simplifies overlapping zones and resolution logic, and ensures queries take the shortest, most secure path to their destination, thereby lowering latency and relieving data center bottlenecks.

What deployment options are available for Edge service points and how do they support high availability?

Edge service points can be deployed on BlueCat DNS/DHCP Servers (BDDSes), in virtual environments such as open-source KVM and VMware ESXi, on select Cisco platforms, and in cloud environments including AWS, Azure, and Google Cloud. This flexible deployment model allows organizations to place service points close to clients or workloads to handle any client load and create multiple, geographically distributed resolution paths. By provisioning many service points and using Edge’s intelligent forwarding, the solution increases resilience and fault tolerance for critical infrastructure, improving overall availability for hybrid and multicloud DNS resolution.

What security, policy, and observability capabilities does Edge provide for DNS traffic?

Edge applies security policies and forwarding rules at the first hop, enabling admins to block, redirect, or monitor DNS requests based on client identity, accessed resources, or detected security events. It tames conditional forwarding rules through namespace-based intelligent forwarding and enforces policies such as blocking or redirecting queries per configured rules. For observability, Edge collects DNS query and response information, offers logging and graphical analysis with powerful query log filters, and can export DNS data to popular SIEMs to support diagnostics, investigations, and centralized monitoring.

Overcome DNS resolution bottlenecks and reduce latency

In a hybrid and multicloud world, DNS queries can potentially resolve to multiple locations. To achieve highly performant and available DNS, network teams need an automated way to configure the shortest and most secure resolution path and reduce latency. Without complete visibility and control at the first hop of any DNS query, network admins cannot keep up with rapid changes to DNS configuration in multicloud environments or relieve data center bottlenecks to resolve queries for endpoints across wide, distributed networks.

The solution: BlueCat Edge

BlueCat Edge adds a much-needed layer of visibility, control, and detection for DNS. As the first hop of any DNS query, Edge works to intelligently direct DNS traffic, tame conditional forwarding rules, block DNS queries based on network and security policies, and help monitor and collect all DNS query and response information for diagnostics and investigations.

Services, apps, and data can reside simultaneously in different clouds and regions across different internal and external zones. Instead of manually maintaining reams of conditional forwarding rules across multiple authoritative DNS servers, Edge uses intelligent forwarding via service points to set conditions and direct queries to the right destination.

BlueCat interface displaying DNS query timestamps, IP addresses, query details, and inspect client activity button

Benefits

Improve performance

Provision multiple optimized resolution paths, and simplify overlapping zones and DNS resolution paths to improve network performance.

Prevent downtime

Increase the resilience of critical infrastructure by resolving hybrid and multicloud DNS with highly available and fault-tolerant service points.

Accessible and compliant by default

Edge is unconditionally compliant with WACG 2.2 AA standards to empower every user.

Deploy anywhere

To handle any client load, deploy Edge service points on BlueCat DNS/DHCP Servers (BDDSes), in virtual environments such as open-source KVM and VMware ESXi, on select Cisco platforms, and in cloud environments (AWS, Azure, and Google Cloud).

Edge service points

Edge service points, illustrated below, are first-hop DNS resolvers. They intelligently apply security policies and forwarding rules to every query, ensuring DNS traffic moves through the cloud safely and optimally.

BlueCat Edge service point architecture for internal and external DNS queries with caching, security, and Splunk analytics

Figure 1. Edge architecture

Features

Intelligent forwarding using namespaces

Route traffic from remote offices or client networks to the most appropriate resolution path using match or exception domain lists.

Policy configuration

Admins can apply policies to block, redirect, or monitor DNS requests based on clients, resources accessed, or detected security issues.

Zero-touch deployment

Deploy unlimited numbers of virtual service points with hosted services without making changes to your existing DNS infrastructure, and at no extra cost.

Edge Resolver

Simplify and accelerate DNS resolution for hybrid and multicloud environments.

Logging and reporting

Tame big data problems with powerful query log filters, graphical analysis, and exporting DNS data to popular SIEMs.

Next steps

Learn how you can intelligently direct your network’s DNS traffic and tame conditional forwarding rules.

BlueCat’s Intelligent Network Operations (NetOps)

BlueCat’s Intelligent NetOps solutions provide the analytics and intelligence needed to enable, optimize, and secure the network to achieve business goals. With an Intelligent NetOps suite, organizations can more easily change and modernize the network as business requirements demand.

Isometric blue UI tiles showing gear, shield, chip, and magnifying glass icons on a grid background

📣  Now live: Explore BlueCat Horizon, our SaaS-first Intelligent NetOps platform.