150
Establishing your network
About the security gateway’s implementation of DNS
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
“DNS Recursion Record Properties—General tab”
Configuring DNS for an enclave network with a DNS root server record
DNS lookups begin with the root servers, which send back either the DNS information requested or the
name server that can get the requester closer to the DNS information they seek.
The most current version of this root server list is found at:
ftp://ftp.internic.net/domain/named.cache
The security gateway has the current list of root servers hard-coded in the software. You can add a root
server record to override this list of servers that DNS uses to find top-level domain information.
Adding a new record instructs the security gateway to ignore the hard-coded servers, and use only the
defined entry. If the DNS server that is pointed to in the new root server record is unavailable, DNS
lookups fail; they do not fall back to the hard-coded list.
Use this feature if you have a security gateway protecting an enclave network. In this case, the enclave
security gateway cannot directly access Internet root servers because traffic is blocked by the
perimeter security gateway. Therefore, you must configure the enclave security gateway to use the
perimeter security gateway as a root server. You would also do this if you have no access to the Internet
(if you have your own internal root servers).
You need a corresponding host record to resolve the configured root server name.
Prerequisites
Complete the following task before beginning this procedure:
■
“Identifying a host in a domain with a DNS host record”
To configure DNS for an enclave network with a DNS root server record
1
In the SGMI, in the left pane, under Assets, click
Network
.
2
In the right pane, on the DNS tab, click
New > DNS Root Server Record
.
3
In the DNS Root Server Record Properties dialog box, on the General tab, do the following:
4
Optionally, on the Description tab, type a more detailed description than what you typed in the
Caption text box.
5
Click
OK
.
Enable
To enable the DNS root server record, click
Enable
.
Server name
Type the fully qualified domain name for the DNS root server.
Accessibility
The Private status is displayed.
This field is read-only.
Caption
Type a brief description of the DNS record.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...