Dns Cache Proxy; Enable Dns Cache; List Of Clients Allowed To Used The Dns Cache; Advanced Properties - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

DNS CACHE PROXY

When you send a DNS query to your browser or to an e-mail address, the DNS server will convert
the known domain name (e.g. www.company.com or smtp.company.com) into an IP address
and communicate it to you.
The DNS cache proxy allows storing the response and IP address communicated earlier by the
server in the firewall's memory. As such, whenever a similar query is sent, the firewall will respond
more quickly on behalf of the server and will provide the saved IP address.
The DNS cache proxy window consists of a single screen, divided into two sections:
A table listing the DNS clients allowed to use the cache.
l
A drop-down menu allowing the definition of advanced properties.
l

Enable DNS cache

This option allows the DNS cache proxy  to run: when a DNS query is sent to the firewall, it will be
processed by the DNS cache.

List of clients allowed to used the DNS cache

DNS client [host, network, range, group]:
The clients that appear in the list can send DNS queries through the firewall.
Add
Delete
In transparent mode, the selected clients will benefit from the DNS cache proxy, while other
requests will be subject to filtering.

Advanced properties

Cache size (in bytes):
The maximum size allocated to the DNS cache depends on your firewall's model.
Transparent mode
(intercepts all DNS
queries sent by
authorized clients)
Page 110/448
By clicking on this button, a new line will be added to the top of the table. The arrow to
the right of the empty field allows adding a DNS client. You may select this client from
the object database that appears. This may be a host, network, address range or even
a group.
First, select the DNS client you wish to remove from the list. A window will appear with
the following message: "Remove selected DNS client?" " You can confirm the deletion
or Cancel the operation.
NOTE
As its name implies, the purpose of this option is to make the Stormshield Network
Firewall's DNS service transparent. As such, when this option is enabled, the
redirection of DNS traffic to the DNS cache will be invisible to users who will get the
impression they are accessing their DNS servers.
In transparent mode, all queries will be intercepted, even if they are going to DNS
servers others than the firewall. The responses will be saved in memory for a certain
duration to avoid resending known requests.
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
DNS CACHE PROXY

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents