Chapter 25
Specific settings and troubleshooting
384
To avoid unintentional dialing based on DNS requests,
WinRoute
allows definition of rules
where DNS names are specified for which the line can be dialed or not. To define these rules,
click on
Advanced
in
Configuration
→
Interfaces
(in the
A Single Internet Link — Dial on De-
mand
mode).
Figure 25.7
Dial on demand rules (for dialing based on DNS queries)
Either full
DNS name
or only its end or beginning completed by an asterisk (
*
) can be specified
in the rule. An asterisk may stand for any number of characters.
Rules are ordered in a list which is processed from the top downwards (rules order can be
modified with the arrow buttons at the right side of the window). When the system detects
the first rule that meets all requirements, the desired action is executed and the search is
stopped. All DNS names missing a suitable rule will be dialed automatically by
DNS Forwarder
when demanded.
In
Actions
for DNS name, you can select either the
Dial
or the
Ignore
option. Use the second
option to block dialing of the line in response to a request for this DNS name. The
Dial
action
can be used to create complex rule combinations. For example, dial can be permitted for one
name within the domain and denied for the others (see figure
Dial of local DNS names
Local DNS names are names of hosts within the domain (names that do not include a do-
main).
Example:
The local domain’s name is
company.com
. The host is called
pc1
. The full name of the
host is
pc1.company.com
whereas local name in this domain is
pc1
.
Local names are usually stored in the database of the local DNS server (in this example,
the names are stored in the
hosts
file at the
WinRoute
host that uses
DNS forwarder
).
Set by default,
DNS Forwarder
does not dial these names as names are considered non-
existent unless they can be found in the local DNS database.
If the primary server of the local domain is located outside of the local network, it is
necessary that the
DNS Forwarder
also dials the line if requests come from these names.
Содержание Firewall6
Страница 1: ...Kerio WinRoute Firewall 6 Administrator s Guide Kerio Technologies...
Страница 129: ...8 5 HTTP cache 129...
Страница 404: ...404...