157
Establishing your network
About the security gateway’s implementation of DNS
Enabling reverse lookups
When the security gateway’s secure proxies look up a host name for an IP address, it is referred to as a
reverse lookup. The secure proxies perform reverse lookups to prevent untrusted sites from
pretending to be associated with trusted host names.
Reverse lookups are disabled by default. Enable reverse lookups if you want the additional DNS checks
to be performed and if you are confident that your DNS implementation resolves reverse name
lookups. Otherwise, leave them disabled. Enabling them without a proper DNS implementation can
adversely affect system performance.
Prerequisites
None.
To enable reverse lookups
1
In the SGMI, in the left pane, under Assets,
click
Asset Parameters
.
2
In the right pane, under Asset Parameters, check
Enable reverse lookups
.
3
To modify the timeout, in the Reverse lookup timeout (seconds) text box, type a timeout value.
4
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
None.
Solving DNS problems
Name service problems can prevent connections, if applications cannot resolve addresses. DNS issues
can also slow performance due to DNS requests having to timeout at least once before being properly
handled. Subsequently, every connection using a lookup is slowed.
The procedures in this section help to diagnose the most common DNS problems. Diagnosing a
problem with name service depends heavily upon your network configuration. If you do not administer
the whole network, coordinate with the people who do. If you do not have much hands-on experience
implementing DNS, work with someone who does.
This section helps you to:
■
■
Understand why inside DNS lookups do not work
■
Ensure DNSd is running
You may need to verify that your DNS implementation is running by sending a request and seeing if
you receive a response using the nslookup or dig command. If that does not show you what you want,
use the following procedure.
Prerequisites
None.
To ensure DNSd is running
1
In the SGMI, under Assets, click
Network
.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...