ZyXEL Communications USG FLEX H Series User Manual page 363

Table of Contents

Advertisement

Chapter 24 System
The Zyxel Device can ask a DNS server to use recursion to resolve its DNS client requests. If recursion on
the Zyxel Device or a DNS server is disabled, they cannot forward DNS requests for resolution.
A Domain Name Server (DNS) amplification attack is a kind of Distributed Denial of Service (DDoS)
attack that uses publicly accessible open DNS servers to flood a victim with DNS response traffic. An
open DNS server is a DNS server which is willing to resolve recursive DNS queries from anyone on the
Internet.
In a DNS amplification attack, an attacker sends a DNS name lookup request to an open DNS server
with the source address spoofed as the victim's address. When the DNS server sends the DNS record
response, it is sent to the victim. Attackers can request as much information as possible to maximize the
amplification effect.
Configure the Security Option Control section in the System > DNS & DDNS > DNS screen if you suspect
the Zyxel Device is being used (either by hackers or by a corrupted open DNS server) in a DNS
amplification attack.
USG FLEX H Series User's Guide
363

Advertisement

Table of Contents
loading

Table of Contents