HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Command Referen - Page 117

dns trust-interface, ip host

Page 117 highlights

Related commands dns proxy enable dns trust-interface Use dns trust-interface to specify the DNS trusted interface. Use undo dns trust-interface to remove the specified DNS trusted interface. If no interface is specified, the undo dns trust-interface command removes all DNS trusted interfaces. Syntax dns trust-interface interface-type interface-number undo dns trust-interface [ interface-type interface-number ] Default No trusted interface is specified. Views System view Predefined user roles network-admin Parameters interface-type interface-number: Specifies an interface by its type and number. Usage guidelines By default, an interface obtains DNS suffix and DNS server information from DHCP. A network attacker may act as the DHCP server to assign wrong DNS suffix and DNS server address to the device. As a result, the device fails to obtain the resolved IP address or may get the wrong IP address. With the DNS trusted interface specified, the device only uses the DNS suffix and DNS server information obtained through the trusted interface to avoid attack. This configuration is applicable to both IPv4 and IPv6. You can configure a maximum of 128 DNS trusted interfaces on the device. Examples # Specify VLAN-interface 2 as the DNS trusted interface. system-view [Sysname] dns trust-interface vlan-interface 2 ip host Use ip host to create a host name-to-IPv4 address mapping. Use undo ip host to remove a mapping. Syntax ip host host-name ip-address [ vpn-instance vpn-instance-name ] undo ip host host-name ip-address [ vpn-instance vpn-instance-name ] 109

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257

109
Related commands
dns
proxy
enable
dns trust-interface
Use
dns
trust-interface
to specify the DNS trusted interface.
Use
undo
dns
trust-interface
to remove the specified DNS trusted interface. If no interface is specified, the
undo
dns
trust-interface
command removes all DNS trusted interfaces.
Syntax
dns
trust-interface
interface-type
interface-number
undo
dns
trust-interface
[
interface-type
interface-number
]
Default
No trusted interface is specified.
Views
System view
Predefined user roles
network-admin
Parameters
interface-type
interface-number
: Specifies an interface by its type and number.
Usage guidelines
By default, an interface obtains DNS suffix and DNS server information from DHCP. A network attacker
may act as the DHCP server to assign wrong DNS suffix and DNS server address to the device. As a
result, the device fails to obtain the resolved IP address or may get the wrong IP address. With the DNS
trusted interface specified, the device only uses the DNS suffix and DNS server information obtained
through the trusted interface to avoid attack.
This configuration is applicable to both IPv4 and IPv6.
You can configure a maximum of 128 DNS trusted interfaces on the device.
Examples
# Specify VLAN-interface 2 as the DNS trusted interface.
<Sysname> system-view
[Sysname] dns trust-interface vlan-interface 2
ip host
Use
ip host
to create a host name-to-IPv4 address mapping.
Use
undo ip host
to remove a mapping.
Syntax
ip
host
host-name
ip-address
[
vpn-instance
vpn-instance-name
]
undo ip host
host-name
ip-address
[
vpn-instance
vpn-instance-name
]