HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 93

Configuring the DNS trusted interface, Displaying and maintaining IPv4 DNS

Page 93 highlights

DNS servers. In some scenarios, the DNS server only responds to DNS requests sourced from a specific IP address. In such cases, you must specify the source interface for the DNS packets so that the device can always uses the primary IP address of the specified source interface as the source IP address of DNS packets. When sending IPv4 DNS request, the device uses the primary IPv4 address of the source interface as the source IP address of the DNS request. When sending IPv6 DNS request, the device selects an IPv6 address from the addresses configured on the source interface as defined in RFC 3484 as the source IP address of the DNS request. If no IP address is configured on the source interface, the DNS packet fails to be delivered. You can configure only one source interface on the public network or a VPN. When you configure a new source interface, the last configuration takes effect. You can configure the source interface for the public network and a maximum of 1024 VPNs. To specify the source interface for DNS packets: Step 1. Enter system view. 2. Specify the source interface for DNS packets. Command system-view dns source-interface interface-type interface-number [ vpn-instance vpn-instance-name ] Remarks N/A By default, no source interface for DNS packets is specified. If you specify the vpn-instance vpn-instance-name option, make sure the source interface is on the specified VPN. Configuring the DNS trusted interface By default, an interface obtains DNS suffix and domain name server information from DHCP. The network attacker may act as the DHCP server to assign wrong DNS suffix and domain name server address to the device. As a result, the device fails to get the resolved IP address or may get the wrong IP address. With the DNS trusted interface specified, the device only uses the DNS suffix and domain name server information obtained through the trusted interface to avoid attack. To configure the DNS trusted interface: Step 1. Enter system view. Command system-view 2. Specify the DNS trusted interface. dns trust-interface interface-type interface-number Remarks N/A By default, no DNS trusted interface is specified. You can configure up to 128 DNS trusted interfaces. Displaying and maintaining IPv4 DNS Execute display commands in any view and reset commands in user view. 84

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

84
DNS servers. In some scenarios, the DNS server only responds to DNS requests sourced from a specific
IP address. In such cases, you must specify the source interface for the DNS packets so that the device
can always uses the primary IP address of the specified source interface as the source IP address of DNS
packets.
When sending IPv4 DNS request, the device uses the primary IPv4 address of the source interface as the
source IP address of the DNS request. When sending IPv6 DNS request, the device selects an IPv6
address from the addresses configured on the source interface as defined in RFC 3484 as the source IP
address of the DNS request. If no IP address is configured on the source interface, the DNS packet fails
to be delivered.
You can configure only one source interface on the public network or a VPN. When you configure a new
source interface, the last configuration takes effect. You can configure the source interface for the public
network and a maximum of 1024 VPNs.
To specify the source interface for DNS packets:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify the source
interface for DNS
packets.
dns source-interface
interface-type
interface-number
[
vpn-instance
vpn-instance-name
]
By default, no source interface for
DNS packets is specified.
If you specify the
vpn-instance
vpn-instance-name
option, make
sure the source interface is on the
specified VPN.
Configuring the DNS trusted interface
By default, an interface obtains DNS suffix and domain name server information from DHCP. The
network attacker may act as the DHCP server to assign wrong DNS suffix and domain name server
address to the device. As a result, the device fails to get the resolved IP address or may get the wrong IP
address. With the DNS trusted interface specified, the device only uses the DNS suffix and domain name
server information obtained through the trusted interface to avoid attack.
To configure the DNS trusted interface:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify the DNS trusted
interface.
dns trust
-
interface
interface-type
interface-number
By default, no DNS trusted
interface is specified.
You can configure up to 128 DNS
trusted interfaces.
Displaying and maintaining IPv4 DNS
Execute
display
commands in any view and
reset
commands in user view.