Vigor3900 Series User’s Guide
307
Item Description
Check DNS Reply
Strictly
In default, Vigor router does not check that unsigned DNS
replies are legal or not: they are assumed to be valid and
passed on. This does not protect against an attacker forging
unsigned replies for signed DNS zones, but it is fast. If this
option is enabled, Vigor router will check the zones of
unsigned replies to ensure that unsigned replies are allowed
in those zones. The cost of this is more upstream queries and
slower performance.
Enable
– It will check if the unsigned DNS replies are
unsigned or not.
Disable
– The unsigned DNS replies will be regarded as
“legal”. It is default setting.
DNS Server check for
DNS Security
Vigor router will check and display if the DNS servers listed
in WAN profiles supporting DNS security or not.
Apply
Click it to save the configuration.
Cancel
Click it to discard the settings configured in this page.
VoIPon www.voipon.co.uk [email protected] Tel: (0)330 088 0195 Fax: +44 (0)1245 808299