In the Advanced system settings, you can configure various settings, such as an SSL Certificate policy and SOA record defaults, among others. There are several categories of advanced system settings, which you can refer to below for more information:
- SSL (Secure Sockets Layer)
- SOA record defaults in new zones
- Miscellaneous settings
SSL
Certificates enable the use of HTTPS when communicating with external web services, such as Azure. Configure an SSL Certificate policy with the following settings:
- SSL Certificate policy
- Determines the SSL Certificate policy applied to the Cloud Integration feature. Select whether the SSL Certificate policy is Strict or Permissive.
SOA record defaults in new zones
Use the following settings to configure SOA record defaults in new DNS zones:
- TTL of SOA record
- Specify the default TTL (Time-to-Live) value to use for the SOA record of new zones.
- Hostmaster
- Specifies the default value to use for the
Hostmasterfield in the SOA record of new zones. - Refresh
- Specify the default value to use for the
Refreshfield in the SOA record of new zones. - Retry
- Specify the default value to use for the
Retryfield in the SOA record of new zones. - Expire
- Specify the default value to use for the
Expiryfield in the SOA record of new zones. - Negative caching (BIND)
- Specify the default value to use for the
Negative Cachingfield in the SOA record of new zones. Only applicable for zones on BIND DNS servers. - Minimum TTL (MS)
- Specify the default TTL (Time-to-Live) value to use for the
TTLfield in the SOA record of new zones. Only applicable for zones on Microsoft DNS servers.
Miscellaneous
The following settings can be configured for various functions:
- Time in minutes between write-outs of API call performance log
- If logging of API query performance is enabled, specify how frequently the log should be written to disk.
- Automatically adjust local zone transfer settings for BIND
- Enable this setting for BIND to automatically optimize the settings related to local (within your network) zone transfers.
- Automatically create reverse (PTR) records
- Enable this setting for DDI orchestrator to automatically create reverse (PTR) records. PTR records are used for reverse DNS lookups, which are used to resolve an IP address to a domain name.
- Perform backup of MS and ISC DHCP servers
- Select this checkbox to enable DDI orchestrator to perform a backup of Microsoft (MS) and Internet Systems Consortium (ISC) Dynamic Host Configuration Protocol (DHCP) servers.
- Default TTL to use for DNS records created in zones for all xDNS profiles
- Specify the default TTL (Time-to-Live) value to use for DNS records created in zones for all xDNS profiles.
- Use Azure activity log to optimize DNS synchronization
- When enabled, the Azure activity log is monitored for events related to DNS changes, and those changes are synchronized with the DNS server in real-time.
- Use AWS CloudTrail events to optimize DNS synchronization
- Select the checkbox to enable AWS CloudTrail events to be used to optimize DNS synchronization.
- IP ranges/scopes inherit access by default
- When you create a new IP range or scope, it will inherit all access bits from its parent by default. If you want to change this behavior, clear this checkbox.
- Maximum number of blocks that can be temporarily claimed
- To limit the number of blocks that can be temporarily reserved or allocated for use by a specific user, enter the maximum number of blocks.
- Timeout in seconds for named-checkconf
- Enter the timeout value, in seconds, for named-checkconf files.
- Synchronize DNSSEC signed zones immediately after editing
- Select the checkbox to enable the immediate synchronization of DNSSEC signed
zones when they are changed.Note: Enabling this feature can affect the performance of the system.
- Use case sensitive comparison when updating custom properties from scripts
- Select the checkbox to require taking case sensitivity into account when comparing custom properties from scripts.
- Include A/AAAA records when checking for "Edit apex records" access
- Select the checkbox to require the consideration of A and AAAA records when verifying access to edit apex (root) records.
- Web app landing page
- By default, the DDI orchestrator homepage is the landing page for the system. You can change the landing page, if desired, to either the DNS or IPAM page. If you change the landing page, you can select the DDI orchestrator logo in the top left corner of the screen to go to the DDI orchestrator homepage.