DNS Configuration

Domain Name System Support

The security device incorporates Domain Name System (DNS) support, allowing you to use domain names for identifying locations. DNS translation supports the following services:

  • Address Book

  • AutoKey IKE Remote Gateways

  • Syslog

  • Email

  • WebTrends

  • Websense

  • LDAP

  • SecurID

  • RADIUS

  • NetScreen-Global PRO

Note: The server IP addresses for each service above must also accept domain names.

DNS Servers

A DNS keeps a table of the IP addresses associated with domain names. Using DNS makes it possible to reference locations by domain name (such as www.juniper.net) instead of using the routable IPv4 or IPv6 address. For example, the IPv4 address of the DNS server for www.juniper.net is 207.17.137.68.

You can also specify a source (src) interface for the DNS server. When you specify a source interface on the security device, DNS request packets, which are initiated from within the system by the DNS module, are treated as if they are received externally from the source interface you set. With the source interface specified, DNS request packets as with user packets trigger firewall policy lookup and are handled according to the rules of the policy. The source interface can be any interface that matches the zone.

Before you can use DNS names with the services described above, you must configure DNS servers.

To Configure DNS Servers

  1. Enter the necessary information:

Host Name: Enter the name of the security device. The default name is based on the model of the device, for example ns208, ns500.

Domain Name: Enter the domain name. You must fill this in if you want Domain Name System (DNS) name/address resolution to work.

Primary DNS Server: Enter the IP address of your primary DNS server. To enhance security, specify a Src Interface to trigger policy lookup for DNS requests.

Secondary DNS Server: Enter the IP address of your secondary DNS server. To enhance security, specify a Src Interface to trigger policy lookup for DNS requests.

Tertiary DNS Server: Enter the IP address of your tertiary DNS server. To enhance security, specify a Src Interface to trigger policy lookup for DNS requests.

DNS refresh every day at: Allows you to specify a daily time (in 24 hour format) or an interval of  time at which the NetScreen device resolves DNS settings.

Clicking the Refresh button forces the device to do a DNS lookup. For more information on the functions of the Refresh button, see "DNS Lookup".

  1. Click Apply to save your configuration.

DNS Lookup

Security device lookup is subject to several conditions:

DNS Report

To view a DNS lookup report, click Show DNS Table. The report lists the following information: