11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Configuring Proxied Servicesvalid transaction signature but no valid key, processingsteps that initialize important variables (notably therequired buffer size) are skipped. Subsequent functioncalls make invalid assumptions about the size of therequest buffer, which can cause requests with legitimatetransaction signatures and keys to trigger a buffer overflow.Used in conjunction with other attack tools, this typeof attack results in a server crash and the attacker gainingunauthorized access to your root shell through an outboundTCP connection. Using this connection, the attackercan execute arbitrary code on your network.Some versions of BIND are also vulnerable to another typeof buffer overflow attack that exploits how NXT (or next)records are processed. Attackers can set the value of a keyvariable such that the server crashes and the attacker gainsunauthorized access. The DNS proxy protects your DNSservers from both the TSIG and NXT attacks, along with anumber of other types of DNS attacks. For more informationon the DNS proxy, see the DNS Proxy section of thefollowing collection of FAQs:https://support.watchguard.com/advancedfaqs/proxy_main.aspNOTEUnless you have a DNS server for public use, you should notuse this proxy.Adding the DNS Proxy ServiceWhen you add the DNS proxy, you can best protect yournetwork by applying the proxy to both inbound and outboundtraffic. You can also set up the DNS proxy so thatany denied packets (inbound or outbound) generate logrecords. You can use LogViewer to check your log files forrecords that indicate DNS attacks, which in turn lets yousee how often and from where you were attacked.1 On the toolbar, click the Add Services icon.2 Expand the Proxies folder.A list of pre-configured proxies appears.156 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!