system-view
The system view is displayed.
Step 2
Run:
dns proxy enable
DNS proxy is enabled.
Or, run:
dns relay enable
DNS relay is enabled.
DNS relay is similar to DNS proxy. The difference is that the DNS proxy searches for DNS
entries saved in the local cache after receiving DNS query messages from DNS clients. The DNS
relay, however, directly forwards DNS query messages to the DNS server, reducing the
workload.
Step 3
Run:
dns spoofing
ip-address
DNS spoofing is enabled and an IP address in response messages is specified.
----End
4.4.4 (Optional) Setting the Aging Time of DNS Entries
This section describes how to set the Aging Time of DNS Entries.
Context
When the DNS proxy or relay is attacked, the DNS table becomes full. As a result, the DNS
proxy or relay cannot resolve new domain names into IP addresses. To solve the problem, you
can set the aging time of DNS entries so that the local routing device can delete expired DNS
entries.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
dns proxy enable
DNS proxy is enabled.
Or run:
dns relay enable
DNS relay is enabled.
DNS relay is similar to DNS proxy. The difference is that the DNS proxy searches for DNS
entries saved in the local cache after receiving DNS query messages from DNS clients. The DNS
relay, however, directly forwards DNS query messages to the DNS server, reducing the
workload.
Huawei AR150&200 Series Enterprise Routers
Configuration Guide - IP Service
4 DNS Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
89