DNS Filter features in TMG

Source: Internet
Author: User

Before viewing the System node on TMG, you see a DNS filter feature in the application filter, what is the main function of this feature? Or what is its main function?

First of all, the role of a DNS filter is primarily to detect DNS attacks against DNS attacks.

Next, we'll do a detailed analysis:

The Forefront TMG Domain Name System (DNS) filter intercepts and analyzes all inbound DNS traffic destined for the internal network and other protected networks. If DNS attack detection is enabled, you can specify a DNS filter to check for suspicious activities of the following types:

DNS Host name overflow-when a DNS response to a host name exceeds 255 bytes, an application that does not check the host name length may overflow the internal buffer when replicating the host name, allowing remote attackers to execute arbitrary commands on the target computer.

DNS Length overflow – When DNS responses to IP addresses exceed 4 bytes, some applications that perform DNS lookups overflow the internal buffer, allowing remote attackers to execute arbitrary commands on the target computer. Forefront TMG also checks whether the value of rdlength exceeds the size of the rest of the DNS response.

More Wonderful content: http://www.bianceng.cnhttp://www.bianceng.cn/Servers/DNS/

DNS zone transfer-client systems use DNS client applications to transfer zones from internal DNS servers.

When an offensive packet is detected, the system discards the packets and generates an event that triggers a DNS intrusion alert. Alerts can be configured to notify you when an attack is detected. A DNS zone transfer intrusion alert is triggered when 5 DNS intrusion events are generated within one minute of a DNS zone transfer. By default, these alerts are not triggered again until the applicable predefined alerts are triggered before they are manually reset.

One of the previous posts was to address the inability to access some of the http://connect.qq.com/in the TMG by disabling the compression filter under the Web filter, and here today, although not the problem encountered, but I understand the function of this filter, so share, Hey.

This article is from the "Clumsy birds have" blog, please be sure to keep this source http://tingdongwang.blog.51cto.com/1056852/687537

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.