146
Establishing your network
About the security gateway’s implementation of DNS
Pointing to an external name server with a DNS forwarder record
Generally, it is unnecessary to create forwarders on the security gateway. A forwarder record points to
an external server that is used to redirect DNS requests. If you decide that you would prefer not to have
the security gateway perform DNS lookups, but instead offload this work to another DNS server,
configure a forwarder record. The DNS proxy still handles the exchange of information between the
requesting client and the DNS server that the request was forwarded to, passing the original DNS
request to the destination DNS server, and then sending the reply back to the client.
If you do not configure any forwarders, the DNS system performs its own lookups, querying a root
name server for the domain’s authoritative DNS server.
Prerequisites
None.
To point to an external name server with a DNS forwarder record
1
In the SGMI, in the left pane, under Assets, click
Network
.
2
In the right pane, on the DNS tab, click
New > DNS Forwarder Record
.
3
In the DNS Forwarder Record Properties dialog box, on the General tab, do the following:
4
Optionally, on the Description tab, in the text box, type a more detailed description than you typed
in the Caption text box.
5
Click
OK
.
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
“DNS Forwarder Record Properties—General tab”
Identifying a host in a domain with a DNS host record
A host record identifies either a host name or IP address in a given domain. This type of record serves a
dual purpose, acting as either an A (address) record, which resolves a name to an address, or a PTR
(pointer) record, which resolves an address to a name. You can also assign an alias, which is a nickname
for the same domain name. DNS requests originating external to the security gateway must use the
fully qualified host name.
Prerequisites
None.
Enable
To enable the DNS forwarder record, check
Enable
.
Accessibility
The Private status is displayed.
You cannot select Public; it must be a private interface.
IP address
Type the IP address of the external DNS server.
Caption
Type a brief description of the DNS forwarder record.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...