11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring the DNS Proxy ServiceGET www.mydomain.com / HTTP/1.1The proxy server then forwards this request to the Webserver mentioned in the GET request.To set up an external caching proxy server:1 Configure an external proxy server, such as MicrosoftProxy Server 2.0.2 Open Policy Manager with your current configuration.3 Double-click the icon for your HTTP proxy service.This can be either Proxy, HTTP, or Proxied-HTTP.4 Click the Properties tab. Click the Settings button.5 Select the checkbox marked Use Caching Proxy Server.6 In the fields below the checkbox, enter the IP addressand TCP port of the caching proxy server. Click OK.7 Save this configuration to the <strong>Firebox</strong>.Configuring the DNS Proxy ServiceInternet domain names (such as <strong>WatchGuard</strong>.com) arelocated and translated into IP addresses by the domainname system (DNS). DNS lets users navigate the Internetwith easy-to-remember “dot-com” names by seamlesslytranslating the domain name into an IP address that servers,routers, and individual computers understand. Ratherthan try to maintain a centralized list of domain names andcorresponding IP addresses, smaller lists are distributedacross the Internet.The Berkeley Internet Name Domain (BIND) is a widelyused implementation of DNS. Some versions of BIND canbe vulnerable to attacks that cause a buffer overflow, whichcrash the targeted server and enable the attacker to gainunauthorized access to your network.One attack uses a flaw in the transaction signature (TSIG)handling code. When BIND encounters a request with a<strong>User</strong> <strong>Guide</strong> 155

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!