Security Option Control; Editing A Security Option Control - ZyXEL Communications USG40 User Manual

Zywall/usg series
Hide thumbs Also See for USG40:
Table of Contents

Advertisement

The following table describes the labels in this screen.
Table 353 Configuration > System > DNS > MX Record Add
LABEL
Domain Name
IP Address/FQDN
OK
Cancel

43.6.12 Security Option Control

Configure the Security Option Control section in the Configuration > System > DNS screen
(click Show Advanced Settings to display it) if you suspect the ZyWALL/USG is being used by
hackers in a DNS amplification attack.
One possible strategy would be to deny Query Recursion and Additional Info from Cache in the
default policy and allow Query Recursion and Additional Info from Cache only from trusted
DNS servers identified by address objects and added as members in the customized policy.

43.6.13 Editing a Security Option Control

Click a control policy and then click Edit to change allow or deny actions for Query Recursion
and Additional Info from Cache.
Figure 580 Configuration > System > DNS > Security Option Control Edit (Customize)
Chapter 43 System
DESCRIPTION
Enter the domain name where the mail is destined for.
Enter the IP address or Fully-Qualified Domain Name (FQDN) of a mail server that
handles the mail for the domain specified in the field above.
Click OK to save your customized settings and exit this screen.
Click Cancel to exit this screen without saving
ZyWALL/USG Series User's Guide
837

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents