HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 92

Configuring DNS spoofing, Specifying the source interface for DNS packets

Page 92 highlights

A DNS proxy forwards an IPv4 name query first to IPv4 DNS servers, and if no reply is received, it forwards the request to IPv6 DNS servers. The DNS proxy forwards an IPv6 name query first to IPv6 DNS servers, and if no reply is received, it forwards the request to IPv4 DNS servers. To configure the DNS proxy: Step 1. Enter system view. Command system-view 2. Enable DNS proxy. dns proxy enable • Specify a DNS server IPv4 address: dns server ip-address [ vpn-instance vpn-instance-name ] 3. Specify a DNS server IP address. • Specify a DNS server IPv6 address: ipv6 dns server ipv6-address [ interface-type interface-number ] [ vpn-instance vpn-instance-name ] Remarks N/A By default, DNS proxy is disabled. Use at least one command. By default, no DNS server IP address is specified. Configuring DNS spoofing DNS spoofing is effective only when: • The DNS proxy is enabled on the device. • No DNS server or route to any DNS server is specified on the device. Follow these guidelines when you configure DNS spoofing: • You can configure only one replied IPv4 address and one replied IPv6 address for the public network or a VPN. If you use the command multiple times, the most recent configuration takes effect. • You can configure DNS spoofing for the public network and a maximum of 1024 VPNs. To configure DNS spoofing: Step 1. Enter system view. 2. Enable DNS proxy. 3. Enable DNS spoofing and specify the translated IP address. Command system-view dns proxy enable • Specify a translated IPv4 address: dns spoofing ip-address [ vpn-instance vpn-instance-name ] • Specify a translated IPv6 address: ipv6 dns spoofing ipv6-address [ vpn-instance vpn-instance-name ] Remarks N/A By default, DNS proxy is disabled. Use at least one command. By default, no translated IP address is specified. Specifying the source interface for DNS packets By default, the device uses the primary IP address of the output interface of the matching route as the source IP address of a DNS request. Therefore, the source IP address of the DNS packets may vary with 83

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

83
A DNS proxy forwards an IPv4 name query first to IPv4 DNS servers, and if no reply is received, it
forwards the request to IPv6 DNS servers. The DNS proxy forwards an IPv6 name query first to IPv6 DNS
servers, and if no reply is received, it forwards the request to IPv4 DNS servers.
To configure the DNS proxy:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable DNS proxy.
dns proxy enable
By default, DNS proxy is
disabled.
3.
Specify a DNS server IP
address.
Specify a DNS server IPv4 address:
dns server
ip-address
[
vpn-instance
vpn-instance-name
]
Specify a DNS server IPv6 address:
ipv6 dns server
ipv6-address
[
interface-type interface-number
]
[
vpn-instance
vpn-instance-name
]
Use at least one command.
By default, no DNS server IP
address is specified.
Configuring DNS spoofing
DNS spoofing is effective only when:
The DNS proxy is enabled on the device.
No DNS server or route to any DNS server is specified on the device.
Follow these guidelines when you configure DNS spoofing:
You can configure only one replied IPv4 address and one replied IPv6 address for the public
network or a VPN. If you use the command multiple times, the most recent configuration takes effect.
You can configure DNS spoofing for the public network and a maximum of 1024 VPNs.
To configure DNS spoofing:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable DNS proxy.
dns proxy enable
By default, DNS proxy is disabled.
3.
Enable DNS spoofing and
specify the translated IP
address.
Specify a translated IPv4 address:
dns spoofing
ip-address
[
vpn-instance
vpn-instance-name
]
Specify a translated IPv6 address:
ipv6 dns spoofing
ipv6-address
[
vpn-instance
vpn-instance-name
]
Use at least one command.
By default, no translated IP
address is specified.
Specifying the source interface for DNS packets
By default, the device uses the primary IP address of the output interface of the matching route as the
source IP address of a DNS request. Therefore, the source IP address of the DNS packets may vary with