701
Field descriptions
Assets field descriptions
Proxy Properties: DNS—Miscellaneous tab
The DNS proxy provides name resolution for computers both inside and outside your network without
compromising the privacy of your internal network topology.
The Proxy Properties: DNS dialog box lets you change DNS proxy settings; however, you should not
change default settings unless you completely understand the ramifications or have been instructed to
change these settings by Symantec Technical Support.
Associated tasks
The task that you can perform with this tab is:
■
Maximum time-to-live
Indicates a value to represent how often the DNS proxy refreshes its cache entries.
If a host receives an answer from a DNS server that has a Time to Live that is
longer than the value designated here, the DNS proxy sets the answer’s actual Time
to Live to the value entered here. The configurable range is between 900 (15
minutes) and 2678400 (31 days).
The default is 604800 (seven days).
Serial number format
Each time the DNS database is modified on the host, it creates a unique identifier
for the copy it makes. The DNS proxy uses the DNS last modified timestamp as its
identifier or Serial Number for the database copy. The Serial Number Format text
box lets you select a format for the timestamp identifier. It can be up to 10
characters.
The default is yyyymmddHHM.
Hostmaster
This address should be in the format account.server and not account@server
This address is then passed along to other name servers and can be queried so that
others know who to contact in case of a problem.
Public Hostname
The default LOCAL_HOST is a keyword that is converted to the default system’s
fully qualified domain name internally. This is the DNS name that the system
advertises itself as to name servers and clients on the outside network.
Private Hostname
The default LOCAL_HOST is a keyword that is converted to the default system’s
fully qualified domain name internally. This is the DNS name that the system
advertises itself as to name servers and clients on the inside network.
Table D-159
Proxy Properties: DNS—Miscellaneous tab
Field
Description
Location of host files
The default (%SYSTEM_ETC%) will find the /etc directory on most platforms.
Lets you change the location of the host file.
Allow any hosts to perform a
zone transfer
This check box controls whether zone transfers of information are permitted to all
hosts. This box must be checked for this to occur. Also the nslookup ls command is
implemented by a zone transfer. If checked, users running nslookup can effectively
perform a zone transfer. In that case, you want to disable this option. If unchecked,
only secondary name servers are allowed to handle zone transfers.
This option is disabled by default.
Table D-158
Proxy Properties: DNS—Start of Authority tab
Field
Description
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...