
139
Establishing your network
About the security gateway’s implementation of DNS
The security gateway designates interfaces as either inside or outside. In a caching implementation,
internal interfaces respond to DNS recursive requests from all internal clients or servers. External
interfaces do not respond to any queries they receive, as the security gateway is not authoritative for
any domain, unless a recursion record is configured. The security gateway will respond to hosts listed
within the recursion record.
Figure 5-9
Example network with a caching name server with no internal name server
In
, the security gateway acts as a caching name server, and the client resolvers in the inside
network point to its inside interface. Any name requests from the external network are not answered,
unless a recursion record is set up.
If you do not want to host any domains, and want to configure DNS, you can use a caching name server.
The loopback address and the inside interface are configured automatically after you run the System
Setup Wizard. You do not need to configure any records; however, internal clients (desktops and
servers) must set their resolver to the internal interface of the security gateway.
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...