# Providing zone transfers directly from Netbox DNS

DevFeed: [Providing zone transfers directly from Netbox DNS](<https://devfeed.tech/articles/providing-zone-transfers-directly-from-netbox-dns-41904.md>)

Original publisher: [Read original article](<https://jpmens.net/2026/01/23/providing-zone-transfers-directly-from-netbox-dns/>)

Author: Jan-Piet Mens

Published: 2026-01-22T23:00:00Z

Content type: tutorial

Language: en

Sources: [Jan-Piet Mens](<https://devfeed.tech/sources/jan-piet-mens.md>)

Topics: [NetBox](<https://devfeed.tech/topics/netbox.md>), [NetBox Plugin](<https://devfeed.tech/topics/netbox-plugin.md>), [Server](<https://devfeed.tech/topics/server.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>)

Tags: [catalog](<https://devfeed.tech/tags/catalog.md>), [hmac](<https://devfeed.tech/tags/hmac.md>), [jan-piet-mens](<https://devfeed.tech/tags/jan-piet-mens.md>), [jpm](<https://devfeed.tech/tags/jpm.md>), [jpmens](<https://devfeed.tech/tags/jpmens.md>), [netbox](<https://devfeed.tech/tags/netbox.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [powerdns](<https://devfeed.tech/tags/powerdns.md>), [rfc](<https://devfeed.tech/tags/rfc.md>), [sha256](<https://devfeed.tech/tags/sha256.md>), [tcp](<https://devfeed.tech/tags/tcp.md>)

## AI overview

This technical walkthrough describes netbox-plugin-dns-bridge, a NetBox plugin that provides a small DNS server for AXFR zone transfers. It also explains configuring TSIG keys and using Catalog Zones to provision DNS servers from NetBox.

## Source excerpt

When I first wrote about discovering Netbox DNS I mentioned that the combination of Netbox and the DNS plugin don't actually create a DNS server and zone transfers directly from Netbox are thus impossible. I also went on to describe how there exist programs which can export the data into, say, zone master files for further provisioning DNS servers, but the times, they are changing. Sven Luethi has created a bridge between Peter Eckel's netbox-plugin-dns, the NetBox plugin for managing DNS data, and the DNS. It is called netbox-plugin-dns-bridge (previously netbox-plugin-bind-provisioner) and implements a small DNS server within Netbox which provides for zone transfers (AXFR) in order for compliant clients to transfer whole zones. (Naming things is hard in IT, as we sometimes jokingly say, and I'd like to specifically point out that this is not just for a BIND name server - any compliant name server can transfer zones from netbox-plugin-dns-bridge.) Setting this up is quite straightforward, and is well described in the README. I generate a TSIG key which I configure into the plugin. PLUGINS = [ "netbox_dns", "netbox_dns_bridge", "netbox_dhcp" ] PLUGINS_CONFIG = { ..., "netbox_dns_bridge": { "tsig_keys": { "external": { "keyname": "pext", "algorithm": "hmac-sha256", "secret": "kjMj2tWFtBVn56xvhjxcJRoGjDRgHB5fdAkJRb9Imlg=" } } } } What this does is to configure the provisioner to provide transfers for zones in the "external" view when a transfer is requested with the specified TSIG key. I can configure any number of views as long as I use distinct TSIG keys for each; this is the only way the mini DNS server can determine from which view it should serve a zone (or zones). After restarting Netbox I test a zone transfer using dig(1). The TCP port of the mini DNS server is configurable, but I've used the default here. (Note also how the port is specified in the example named.conf stanza below.) I specify the filename containing the TSIG key, the IP address of the mini DNS