Chapter 44 System
ZyWALL USG Series User’s Guide
913
44.6 DNS Overview
DNS (Domain Name System) is for mapping a domain name to its corresponding IP address and vice
versa. The DNS server is extremely important because without it, you must know the IP address of a
machine before you can access it.
44.6.1 DNS Server Address Assignment
The Zyxel Device can get the DNS server addresses in the following ways.
• The ISP tells you the DNS server addresses, usually in the form of an information sheet, when you sign
up. If your ISP gives you DNS server addresses, manually enter them in the DNS server fields.
• If your ISP dynamically assigns the DNS server IP addresses (along with the Zyxel Device’s WAN IP
address), set the DNS server fields to get the DNS server address from the ISP.
• You can manually enter the IP addresses of other DNS servers.
44.6.2 Configuring the DNS Screen
Click
Configuration > System > DNS
to change your Zyxel Device’s DNS settings. Use the
DNS
screen to
configure the Zyxel Device to use a DNS server to resolve domain names for Zyxel Device system
features like VPN, DDNS and the time server. You can also configure the Zyxel Device to accept or
discard DNS queries. Use the
Network > Interface
screens to configure the DNS server information that
the Zyxel Device sends to the specified DHCP client devices.
A name query begins at a client computer and is passed to a resolver, a DNS client service, for
resolution. The Zyxel Device can be a DNS client service. The Zyxel Device can resolve a DNS query
locally using cached Resource Records (RR) obtained from a previous query (and kept for a period of
time). If the Zyxel Device does not have the requested information, it can forward the request to DNS
servers. This is known as recursion.
The Zyxel Device can ask a DNS server to use recursion to resolve its DNS client requests. If recursion on
the Zyxel Device or a DNS server is disabled, they cannot forward DNS requests for resolution.
A Domain Name Server (DNS) amplification attack is a kind of Distributed Denial of Service (DDoS)
attack that uses publicly accessible open DNS servers to flood a victim with DNS response traffic. An
open DNS server is a DNS server which is willing to resolve recursive DNS queries from anyone on the
Internet.
In a DNS amplification attack, an attacker sends a DNS name lookup request to an open DNS server
with the source address spoofed as the victim’s address. When the DNS server sends the DNS record
response, it is sent to the victim. Attackers can request as much information as possible to maximize the
amplification effect.
Configure the
Security Option Control
section in the
Configuration > System > DNS
screen (click
Show
Advanced Settings
to display it) if you suspect the Zyxel Device is being used (either by hackers or by a
corrupted open DNS server) in a DNS amplification attack.
Summary of Contents for USG110
Page 27: ...27 PART I User s Guide ...
Page 195: ...195 PART II Technical Reference ...
Page 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Page 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Page 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Page 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...