Managing a Resolver Endpoint's Network Security Groups
Add or remove a network security group (NSG) associated with a resolver endpoint.
We recommend that you change security list or NSG security rules to allow traffic bound for UDP Port 53 (and optionally TCP Port 53) on the DNS listener endpoints.
See Private DNS Resolvers and Resolver Endpoints for more information about resolvers and endpoints in the VCN.