Zyxel ZyWALL 1100 [329/438] Dns overview

Zyxel USG 1900 [329/438] Dns overview
Chapter 52 System
ZyWALL / USG (ZLD) CLI Reference Guide
329
52.6 DNS Overview
DNS (Domain Name System) is for mapping a domain name to its corresponding IP address and
vice versa. The DNS server is extremely important because without it, you must know the IP
address of a machine before you can access it.
52.6.1 Domain Zone Forwarder
A domain zone forwarder contains a DNS server’s IP address. The ZyWALL / USG can query the
DNS server to resolve domain zones for features like VPN, DDNS and the time server. A domain
zone is a fully qualified domain name without the host. For example, zyxel.com.tw is the domain
zone for the www.zyxel.com.tw fully qualified domain name.
A name query begins at a client computer and is passed to a resolver, a DNS client service, for
resolution. The ZyWALL / USG can be a DNS client service. The ZyWALL / USG can resolve a DNS
query locally using cached Resource Records (RR) obtained from a previous query (and kept for a
period of time). If the ZyWALL / USG does not have the requested information, it can forward the
request to DNS servers. This is known as recursion.
The ZyWALL / USG can ask a DNS server to use recursion to resolve its DNS client requests. If
recursion on the ZyWALL / USG or a DNS server is disabled, they cannot forward DNS requests for
resolution.
A Domain Name Server (DNS) amplification attack is a kind of Distributed Denial of Service (DDoS)
attack that uses publicly accessible open DNS servers to flood a victim with DNS response traffic.
An open DNS server is a DNS server which is willing to resolve recursive DNS queries from anyone
on the Internet.
In a DNS amplification attack, an attacker sends a DNS name lookup request to an open DNS
server with the source address spoofed as the victim’s address. When the DNS server sends the
DNS record response, it is sent to the victim. Attackers can request as much information as possible
to maximize the amplification effect.

Содержание

Похожие устройства