The DNS firewall can forward requests to other DNS servers of your choice depending on the requested domain. So it acts as a DNS router
To illustrate this feature, we will use our DNS firewall as a centralized DNS server. It will be able to forward requests to unknown domains using public DNS but also to forward requests to our Internal Active Directory domain "articatech.nux" to the Active Directory DNS service
In the spirit of ACLs, a DNS firewall rule is constructed by adding up objects. In our case, we will associate a "domains" object with a "destination DNS server" object
This operation is built into the firewall rules available in the section DNS / DNS Firewall / Firewall rules