155
Establishing your network
About the security gateway’s implementation of DNS
■
Network address translation is not an option when using this method, so you need routable
addresses for your DNS servers.
Forwarding filters require network entities for both the internal (A) and external (B) hosts.
Prerequisites
None.
To use a DNS forwarding filter to pass DNS traffic
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, on the Packet Filters tab, click
New
>
Packet Filter
.
3
In the Packet Filter Properties dialog box, on the General tab, do the following:
4
On the Entry Directions tab, in the Available list, select all of the following protocols, and then click
Add
to move them to the Selected list.
■
A -> B dns_tcp
■
A -> B dns_udp
■
A -> B dns_udp_rev
■
A -> B dns_udp_s2s
■
B -> A dns_tcp
■
B -> A dns_udp
■
B -> A dns_udp_rev
■
B -> A dns_udp_s2s
5
Click
OK
.
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the tool bar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
“Packet Filter Properties—General tab”
■
“Packet Filter Properties—Entry Directions tab”
Optimizing the DNS proxy
The Proxy Properties: DNS dialog box contains controls with pre-set DNS proxy settings.
The DNS proxy is enabled by default. You should not need to change default settings for a typical DNS
proxy deployment.
Filter name
Type a name for this filter.
Action
Select Allow or Deny.
Entity A
Click
Universe
.
Entity B
Select the host entity that you created for this DNS server.
Caption
Type a brief description of the new filter.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...