IP range for tenant domain

Okay, I understand. The problem is that we use a DMZ network that uses secure DNS, and on the firewall, we use other internal network DNS, and they’re resolving differently, causing the firewall to drop the connection. That’s why we’re trying to add the entire segment to avoid that. But if you mention that it’s too large, I have the same security issue.