The Most Underutilized Capability in Infoblox

Every application connection begins with a deceptively simple question.

"Where should I go?"

Whether someone is opening Outlook, logging into a customer portal, or connecting to an internal application, the very first thing their device does is perform a DNS lookup.

For most organizations, that's where the thinking stops.

DNS returns an IP address, the application loads, and everyone moves on.

But modern infrastructure has changed dramatically over the last decade. Applications no longer live in a single data centre behind a single IP address. They're spread across multiple sites, cloud providers, regions and Kubernetes clusters. Organizations invest millions building resilient, highly available environments, yet many still rely on DNS configurations that were designed for a much simpler world.

The result is a disconnect.

Infrastructure has become dynamic, but DNS often remains static.

A Different Question

When an application exists in more than one location, DNS is no longer answering the question:

"What is the IP address of this application?"

Instead, it's answering something far more important:

"Which copy of this application should this user connect to?"

That might seem like a subtle distinction, but it fundamentally changes the role of DNS.

Should users in Europe stay within European infrastructure?

Should new connections avoid a data centre that's experiencing an outage?

Should traffic gradually move to a new Azure deployment during a migration?

These decisions all happen before a single application packet is exchanged.

In other words, DNS has become the first policy decision every application makes.

The Missed Opportunity

This is where I think many Infoblox customers are leaving value on the table.

I've had countless conversations with organizations planning disaster recovery projects, hybrid cloud migrations or global application deployments. Almost every conversation eventually turns toward global traffic management, and many assume they'll need to purchase another product to achieve it.

Ironically, many already have the capability they're looking for.

If you're running Infoblox on X6 licensing, you already own DNS Traffic Control (DTC). Yet, in my experience, very few organizations have taken advantage of it.

That's understandable. DNS isn't exactly the most glamorous part of the infrastructure stack. It quietly does its job every day, so it's rarely revisited unless something breaks.

Where DTC Fits

One of the biggest misconceptions about DNS Traffic Control is that it's designed to replace your load balancer.

It isn't.

Think of the application journey in two steps.

First, someone has to decide which site the user should connect to. Once they arrive, something has to decide which server should handle the request.

Those are different decisions.

Products like F5, Citrix ADC and Azure Load Balancer excel at managing traffic once it reaches a site. DNS Traffic Control makes the decision that comes before that, directing new connections to the most appropriate location based on the policies you define.

The two technologies aren't competitors—they're complementary.

Why It Matters

Once DNS becomes a policy engine instead of a static database, several common infrastructure challenges become much easier to solve.

Disaster recovery becomes more automated because new connections can be directed to a healthy site without someone manually changing DNS records during an outage.

Cloud migrations become less disruptive because traffic can move gradually between on-premises infrastructure and the cloud instead of requiring a single high-risk cutover.

Even application deployments become safer, allowing new environments to receive traffic incrementally before becoming the primary destination.

In every case, the infrastructure remains the same. The only thing changing is the decision DNS makes before the connection begins.

A Conversation Worth Having

One of my favourite parts of working with Infoblox customers isn't introducing them to new technology. It's showing them capabilities they've already invested in but never had the opportunity to explore.

DNS Traffic Control is one of those capabilities.

If your organization has invested in resilient infrastructure, hybrid cloud or disaster recovery, it's worth asking a simple question:

Is your DNS simply answering requests, or is it helping make intelligent decisions?

For many organizations, getting more value from their Infoblox investment doesn't require another product. It simply requires looking at DNS in a different way.

Wondering if DTC is a good fit for your environment?


Every infrastructure is different. We'd be happy to review your current architecture, discuss your goals, and identify where DNS Traffic Control can improve resilience, simplify operations, and support your cloud strategy. Reach out to Spitfire Networks today to schedule a consultation.

Next
Next

Universal DDI vs. Traditional DDI: What's Changed?