This section provides settings related to the prevention of DNS rebinding attacks using FQDN address objects.
To enable DNS binding for FQDN
By default, DNS queries are sent over UDP. The DNS response can include a Truncated flag if the response length exceeds the maximum allowed by UDP.
When the Enable DNS host name lookup over TCP for FQDN option is:
The DNS query times out after one second if no DNS response over TCP is received from the DNS server.
This option is used to gain more IP addresses when sending DNS queries from FQDN over TCP while the Security Appliance receives DNS responses over UDP.
To enable DNS host name lookup over TCP for FQDN
With the DNS Cache Lookup feature, you can view the cached names and IP addresses from DNS resolution. To show the contents of the general DNS cache, click Lookup DNS Cache. A pop-up displays the cache contents.
What |
DNS Server name:
|
DNS Name | Domain name, such as www.SonicWall.com , or IP address. |
IP Address | Resolved IP address. |
TTL (secs) | Time to Live; the TTL value from the DNS response. |
flush | Clicking this flushes the server’s DNS cache entry |
flush all | Clicking this flushes all DNS cache entry of all listed servers |