325
Dial-up DNS addresses have precedence over manually
configured DNS. SX-GATE will fallback to the configured
addresses if no dial-up DNS can be obtained.
14.4.1-B
Client access
Local IP addresses
This setting affects both, the DNS forwarder function of SX-GATE (DNS proxy) and the
name server feature. Forwarding DNS queries to the Internet (recursion) is restricted to
local IPs, which limits the use of SX-GATE as DNS proxy to internal clients. Information
from non-public DNS zones will be served only to local IP addresses.
DNSSec validation
Enable this switch and SX-GATE's DNS forwarder will validate all replies using
DNSSec.
This will increase memory, CPU and network bandwidth
consumption.
Deny answers with private IPs
Enable this switch to prevent DNS rebinding attacks. Forwarding of DNS answers with
private IPs from the networks 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, fe80::/10 and
fc00::/7 will be denied.
Log all DNS queries
With this switch you can log every request processed by the SX-GATE DNS. This
can be especially useful with dial-up Internet connections to detect misconfigured
computers in your LAN which repeatedly trigger an Internet connection with senseless
DNS queries.
Due to the often high frequency of DNS queries, activated
logging can influence the system performance. Furthermore the
size of the logfiles and correspondingly the occupied harddisk
usage may increase rapidly. Thus it is not recommended to
activate this option permanently.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...