Dns spoofing – H3C Technologies H3C SecPath F1000-E User Manual

Page 238

Advertising
background image

213

The DNS proxy simplifies network management. When the DNS server address is changed, you only

need to change the configuration on the DNS proxy instead of on each DNS client.

Figure 121 DNS proxy networking application

DNS proxy operates as follows:

1.

A DNS client considers the DNS proxy as the DNS server, and sends a DNS request to the DNS

proxy, that is, the destination address of the request is the IP address of the DNS proxy.

2.

The DNS proxy searches the local static domain name resolution table after receiving the request.
If the requested information exists in the table, the DNS proxy returns a DNS reply to the client.

3.

If the requested information does not exist in the static domain name resolution table, the DNS
proxy sends the request to the designated DNS server for domain name resolution.

4.

After receiving a reply from the DNS server, the DNS proxy forwards the reply to the DNS client.

NOTE:

With no DNS server or no route to a DNS server specified, the DNS proxy does not forward DNS requests,
or answer the requests from the DNS clients.

DNS spoofing

Figure 122 Network diagram

DNS spoofing is applied to the dial-up network, as shown in

Figure 122

.

DNS client

DNS proxy

IP network

DNS server

DNS client

DNS client

Advertising