18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Configuring Proxies<br />

Configuring proxies<br />

Configuring<br />

proxies<br />

266<br />

Notes on using the DNS proxy<br />

If you have many hosts on a trusted network that point to an external DNS<br />

server, and you want these hosts to use the unbound DNS server on the<br />

<strong>Sidewinder</strong> <strong>G2</strong> instead, you have two options:<br />

• You can modify each <strong>of</strong> the individual hosts to point to the unbound DNS<br />

server.<br />

• You can configure a DNS proxy rule on the <strong>Sidewinder</strong> <strong>G2</strong> that redirects the<br />

DNS traffic from the trusted burb in which the hosts reside to the unbound<br />

DNS server. This may be the preferred option if you have hundreds or<br />

thousands <strong>of</strong> local hosts, because you can make one change on the<br />

<strong>Sidewinder</strong> <strong>G2</strong> rather the hundreds or thousands <strong>of</strong> individual changes.<br />

When defining the DNS proxy rule, be sure to set the following information<br />

on the Source/Dest tab in the Proxy Rule window:<br />

– Set the NAT Address field to Host: localhost.<br />

– Set the Redirect Host field to IPAddr: Firewall. The DNS proxy will not<br />

allow redirection to any other loopback addresses (127.2.0.1).<br />

Important: If your <strong>Sidewinder</strong> <strong>G2</strong> uses split DNS mode, do not create this type <strong>of</strong><br />

proxy rule on the Internet burb, because traffic will bypass the Internet DNS name<br />

server.<br />

The pre-configured <strong>Sidewinder</strong> <strong>G2</strong> proxies consist <strong>of</strong> standard settings and<br />

require very little modification. For most proxies the only configuration decision<br />

to be made is whether to enable or disable each individual proxy. However, the<br />

Admin Console also provides the capability to modify and delete existing<br />

proxies, or to create entirely new proxies.<br />

Tip: You can configure advanced properties for most proxies on a per rule basis<br />

using Application Defenses. For information on configuring Application Defenses,<br />

see Chapter 6. For an overview <strong>of</strong> Application Defenses, see “Application<br />

Defenses” on page 109.<br />

To configure properties for a proxy, start the Admin Console and select<br />

Services Configuration > Proxies. A table appears in the upper portion <strong>of</strong> the<br />

window, listing the available proxies. (Use the scroll bar to browse the entire list<br />

<strong>of</strong> proxies.)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!