Chapter 7 Firewall : Firewall objects : Virtual IPs : Dynamic VIP according to DNS translation
  
Dynamic VIP according to DNS translation
When a dynamic virtual IP is used in a policy, the dynamic DNS translation table is installed along with the dynamic NAT translation table into the kernel. All matched DNS responses will be translated and recorded regardless if they hit the policy. When a client request hits the policy, dynamic NAT translation will occur if it matches a record, otherwise the traffic will be blocked.