DefensePro User Guide
Security Configuration
142
Document ID: RDWR-DP-V0602_UG1201
Configuring Early Blocking of DNS Traffic
Caution:
Modifying the values exposed in the Early Blocking of DNS Traffic feature may impair
the accuracy of the DNS-Flood-attack footprint that DefensePro generates.
When DefensePro detects a new DNS-flood attack (by default, after 10 seconds), the device
generates a DNS-flood-attack footprint and then blocks or drops the relevant flood traffic.
In rare cases, such as very sensitive servers or firewalls, or in laboratory tests, it is required to start
blocking as soon as possible, even if accuracy is compromised. Using Early Blocking of DNS Traffic,
you can configure thresholds for generating DNS-flood-attack footprints, which shorten the time to
start blocking the relevant traffic.
DefensePro generates each footprint using values from fields in the packet header (for example:
Sequence Number, Checksum, and IP ID). The values from fields in the packet header characterize
the attack.
Table 71: DNS Footprint Bypass Parameters
Parameter
Description
Footprint Bypass
Controller
(Read-only) The selected DNS query type for which you are configuring
footprint bypass.
Bypass Field
(Read-only) The selected Bypass Field to configure.
Bypass Status
The bypass option.
Values:
•
Bypass—The DNS Flood Protection module bypasses all possible
values of the selected Bypass Field when generating a footprint.
•
Accept—The DNS Flood Protection module bypasses only the
specified values (if such a value exists) of the selected Bypass Field
when generating a footprint.
Bypass Values
Used if the value of the Bypass Status parameter is Accept. DNS Flood
Protection bypasses only the values of a selected Bypass Type, while it
may use all other values. These values vary according to the Bypass Field
selected. The values in the field must be comma-delimited.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...