Chapter 51 System
ZyWALL / USG (ZLD) CLI Reference Guide
319
51.6 DNS Overview
DNS (Domain Name System) is for mapping a domain name to its corresponding IP address and
vice versa. The DNS server is extremely important because without it, you must know the IP
address of a machine before you can access it.
51.6.1 Domain Zone Forwarder
A domain zone forwarder contains a DNS server’s IP address. The ZyWALL / USG can query the
DNS server to resolve domain zones for features like VPN, DDNS and the time server. A domain
zone is a fully qualified domain name without the host. For example, zyxel.com.tw is the domain
zone for the www.zyxel.com.tw fully qualified domain name.
A name query begins at a client computer and is passed to a resolver, a DNS client service, for
resolution. The ZyWALL / USG can be a DNS client service. The ZyWALL / USG can resolve a DNS
query locally using cached Resource Records (RR) obtained from a previous query (and kept for a
period of time). If the ZyWALL / USG does not have the requested information, it can forward the
request to DNS servers. This is known as recursion.
The ZyWALL / USG can ask a DNS server to use recursion to resolve its DNS client requests. If
recursion on the ZyWALL / USG or a DNS server is disabled, they cannot forward DNS requests for
resolution.
A Domain Name Server (DNS) amplification attack is a kind of Distributed Denial of Service (DDoS)
attack that uses publicly accessible open DNS servers to flood a victim with DNS response traffic.
An open DNS server is a DNS server which is willing to resolve recursive DNS queries from anyone
on the Internet.
In a DNS amplification attack, an attacker sends a DNS name lookup request to an open DNS
server with the source address spoofed as the victim’s address. When the DNS server sends the
DNS record response, it is sent to the victim. Attackers can request as much information as possible
to maximize the amplification effect.
Summary of Contents for ZyWALL USG Series
Page 19: ...19 PART I Introduction ...
Page 20: ...20 ...
Page 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Page 39: ...39 PART II Reference ...
Page 40: ...40 ...
Page 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Page 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Page 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Page 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Page 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Page 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Page 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Page 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Page 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Page 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Page 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Page 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Page 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Page 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Page 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Page 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Page 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Page 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Page 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Page 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Page 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Page 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Page 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Page 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Page 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...