12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring the DNS ProxyConfiguring the DNS ProxyWith the Domain Name System (DNS), you can get access to a web site with an easy-to-remember “dotcom”name. DNS finds the Internet domain name (for example <strong>WatchGuard</strong>.com) and changes it to an IPaddress. The DNS proxy protects your DNS servers from TSIG, NXT, and other DNS attacks. To add theDNS proxy to your Firebox® configuration:1 Add the DNS proxy to Policy Manager. To learn how to add policies to Policy Manager, see“Adding Policies” on page 146.2 Double-click the DNS icon and select the Policy tab.3 Select Allowed from the DNS proxy connections are drop-down list.4 Select the Properties tab.5 In the Proxy drop-down list, select to configure the NS-Outgoing or DNS-Incoming proxy action.6 Click the View/Edit Proxy icon.You can also clone an existing proxy action to create a new proxy action.Configuring general settings for the DNS proxyThe general settings for the DNS Proxy include two protocol anomaly detection rules.Not of class InternetSelect the action to do when the proxy examines DNS traffic that is not of the Internet (IN) class.The default action is to deny this traffic. We recommend that you do not change this defaultaction. Use the Alarm check box to use an alarm for this event. Use the Log check box to writethis event to the log file.Badly formatted querySelect the action when the proxy examines DNS traffic that does not use the correct format. Usethe Alarm check box to use an alarm for this event. Use the Log check box to write this event tothe event log file.Send a log message with summary information for each transactionSelect this check box to record a log message for each DNS connection request. Note that thiscreates a large number of log messages and traffic.180 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!