Chapter 30 System
USG20(W)-VPN Series User’s Guide
553
Figure 377
Configuration > System > DNS > Security Option Control Edit (Customize)
The following table describes the labels in this screen.
30.6.14 Adding a DNS Service Control Rule
Click the
Add
icon in the
Service Control
table to add a service control rule.
Table 239
Configuration > System > DNS > Security Option Control Edit (Customize)
LABEL
DESCRIPTION
Name
You may change the name for the customized security option control policy. The
customized security option control policy is checked first and if an address object match is
not found, the
Default
control policy is checked
Query Recursion
Choose if the USG is allowed or denied to forward DNS client requests to DNS servers for
resolution. This can apply to specific open DNS servers using the address objects in a
customized rule.
Additional Info
from Cache
Choose if the USG is allowed or denied to cache Resource Records (RR) obtained from
previous DNS queries.
Address List
Specifiying address objects is not available in the default policy as all addresses are
included.
Available
This box displays address objects created in
Object > Address
. Select one (or more),
and click the
>
arrow to have it (them) join the
Member
list of address objects that will
apply to this rule. For example, you could specifiy an open DNS server suspect of sending
compromised resource records by adding an address object for that server to the
member list.
Member
This box displays address objects that will apply to this rule.
OK
Click
OK
to save your customized settings and exit this screen.
Cancel
Click
Cancel
to exit this screen without saving
Summary of Contents for ZyWall USG20-VPN
Page 17: ...17 PART I User s Guide ...
Page 18: ...18 ...
Page 99: ...99 PART II Technical Reference ...
Page 100: ...100 ...