Example: Configuring Dns Proxy Entries (Nsm Procedure) - Juniper NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 Manual

Configuring screenos devices guide
Hide thumbs Also See for NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01:
Table of Contents

Advertisement

Example: Configuring DNS Proxy Entries (NSM Procedure)

Copyright © 2010, Juniper Networks, Inc.
In this example, you create two DNS proxy entries that selectively forward DNS queries
to different servers:
A DNS query with a FQDN containing the domain name acme.com goes out tunnel
interface tunnel.1 to the corporate DNS server at 2.1.1.21. When a host sends a DNS
query to
www.acme.com
which resolves the query to 3.1.1.2.
A DNS query with a FQDN containing the domain name acme_eng.com goes out tunnel
interface tunnel.1 to the DNS server at 2.1.1.34. When a host sends a DNS query to the
intranet.acme_eng.com, the device directs the query to this server, which resolves the
query to 3.1.1.5.
All other DNS queries bypass the corporate servers and go out interface ethernet3 to
the DNS server at 1.1.1.23. When the host and domain name is www.juniper.net, the
device automatically bypasses the corporate servers and directs the query to this
server, which resolves the query to 207.17.137.68.
To configure a DNS proxy entry:
Add a NS-208 security device running ScreenOS 5.1.
1.
In the main navigation tree, select Device Manager > Devices, and then double-click
2.
the device to open the device configuration.
Add the tunnel.1 interface:
3.
In the device navigation tree, select Network > Interface.
4.
Click the Add icon and select tunnel interface.
5.
Click
to save the new interface.
OK
6.
Configure the Trust interface:
7.
In the device navigation tree, select Network > Interface.
Double-click the trust interface. The General Properties screen appears.
Select Enable DNS Proxy.
Click OK to save the new interface.
Configure general DNS proxy settings:
8.
In the device navigation tree, select Network > DNS > DNS Proxy.
Select Configure DNS Proxy Instance.
Select Enable.
Add the DNS proxy for acme.com:
9.
, the device automatically directs the query to this server,
Chapter 3: Network Settings
105

Advertisement

Table of Contents
loading

Table of Contents