HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Command Referen - Page 116

dns spoofing, Examples, Syntax, Default, Views, Predefined user roles, Parameters, Usage guidelines

Page 116 highlights

You can specify source interfaces for the public network and a maximum of 1024 VPNs. You can specify only one source interface for the public network or each VPN. Make sure the specified interface is on the VPN specified by the vpn-instance vpn-instance-name option. Examples # Specify VLAN-interface 2 as the source interface for DNS packets on the public network. system-view [Sysname] dns source-interface vlan-interface 2 dns spoofing Use dns spoofing to enable DNS spoofing and specify the IPv4 address to spoof DNS query requests. Use undo dns spoofing to restore the default. Syntax dns spoofing ip-address [ vpn-instance vpn-instance-name ] undo dns spoofing ip-address [ vpn-instance vpn-instance-name ] Default DNS spoofing is disabled. Views System view Predefined user roles network-admin Parameters ip-address: Specifies the IPv4 address used to spoof name query requests. vpn-instance vpn-instance-name: Specifies the name of an MPLS L3VPN, a case-sensitive string of 1 to 31 characters. To enable DNS spoofing function on the public network, do not use this option. Usage guidelines Use the dns spoofing command together with the dns proxy enable command. DNS spoofing enables the DNS proxy to send a spoofed reply with a configured IP address even if it cannot reach the DNS server because no dial-up connection is available. Without DNS spoofing, the proxy does not answer or forward a DNS request if it cannot find a local matching DNS entry or reach the DNS server. You can configure DNS spoofing for the public network and a maximum of 1024 VPNs, and can specify only one replied IPv4 address on the DNS spoofing device for the public network or each VPN. If you use the command multiple times, the most recent configuration takes effect. Examples # Enable DNS spoofing on the public network and specify the IPv4 address 1.1.1.1 to spoof DNS requests. system-view [Sysname] dns proxy enable [Sysname] dns spoofing 1.1.1.1 108

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257

108
You can specify source interfaces for the public network and a maximum of 1024 VPNs. You can specify
only one source interface for the public network or each VPN.
Make sure the specified interface is on the VPN specified by the
vpn-instance
vpn-instance-name
option.
Examples
# Specify VLAN-interface 2 as the source interface for DNS packets on the public network.
<Sysname> system-view
[Sysname] dns source-interface vlan-interface 2
dns spoofing
Use
dns spoofing
to enable DNS spoofing and specify the IPv4 address to spoof DNS query requests.
Use
undo dns spoofing
to restore the default.
Syntax
dns
spoofing
ip-address
[
vpn-instance
vpn-instance-name
]
undo dns spoofing
ip-address
[
vpn-instance
vpn-instance-name
]
Default
DNS spoofing is disabled.
Views
System view
Predefined user roles
network-admin
Parameters
ip-address
: Specifies the IPv4 address used to spoof name query requests.
vpn-instance
vpn-instance-name
: Specifies the name of an MPLS L3VPN, a case-sensitive string of 1 to 31
characters. To enable DNS spoofing function on the public network, do not use this option.
Usage guidelines
Use the
dns spoofing
command together with the
dns proxy enable
command. DNS spoofing enables
the DNS proxy to send a spoofed reply with a configured IP address even if it cannot reach the DNS
server because no dial-up connection is available. Without DNS spoofing, the proxy does not answer or
forward a DNS request if it cannot find a local matching DNS entry or reach the DNS server.
You can configure DNS spoofing for the public network and a maximum of 1024 VPNs, and can specify
only one replied IPv4 address on the DNS spoofing device for the public network or each VPN.
If you use the command multiple times, the most recent configuration takes effect.
Examples
# Enable DNS spoofing on the public network and specify the IPv4 address 1.1.1.1 to spoof DNS
requests.
<Sysname> system-view
[Sysname] dns proxy enable
[Sysname] dns spoofing 1.1.1.1