Before viewing the System node on TMG, you see a DNS filter feature in the application filter, what is the main function of this feature? Or what is its main function?
First of all, the role of a DNS filter is primarily to detect DNS attacks against DNS attacks.
Next, we'll do a detailed analysis:
The Forefront TMG Domain Name System (DNS) filter intercepts and analyzes all inbound DNS traffic destined for the internal network and other protected networks. If DNS attack detection is enabled, you can specify a DNS filter to check for suspicious activities of the following types:
DNS Host name overflow-when a DNS response to a host name exceeds 255 bytes, an application that does not check the host name length may overflow the internal buffer when replicating the host name, allowing remote attackers to execute arbitrary commands on the target computer.
DNS Length overflow – When DNS responses to IP addresses exceed 4 bytes, some applications that perform DNS lookups overflow the internal buffer, allowing remote attackers to execute arbitrary commands on the target computer. Forefront TMG also checks whether the value of rdlength exceeds the size of the rest of the DNS response.
More Wonderful content: http://www.bianceng.cnhttp://www.bianceng.cn/Servers/DNS/
DNS zone transfer-client systems use DNS client applications to transfer zones from internal DNS servers.
When an offensive packet is detected, the system discards the packets and generates an event that triggers a DNS intrusion alert. Alerts can be configured to notify you when an attack is detected. A DNS zone transfer intrusion alert is triggered when 5 DNS intrusion events are generated within one minute of a DNS zone transfer. By default, these alerts are not triggered again until the applicable predefined alerts are triggered before they are manually reset.
One of the previous posts was to address the inability to access some of the http://connect.qq.com/in the TMG by disabling the compression filter under the Web filter, and here today, although not the problem encountered, but I understand the function of this filter, so share, Hey.
This article is from the "Clumsy birds have" blog, please be sure to keep this source http://tingdongwang.blog.51cto.com/1056852/687537