DNS Support for the Rewrite Feature
DNS Expressions
DNS Bind Points
| Bind Points | Description |
|---|---|
| DNS_REQ_OVERRIDE | Override request policy queue. |
| DNS_REQ_DEFAULT | Standard request policy queue. |
| DNS_RES_OVERRIDE | Override response policy queue. |
| DNS_RES_DEFAULT | Standard response policy queue. |
Rewrite Action Types for DNS
-
replace\_dns\_answer\_section—This action replaces the DNS answers section with the defined expression in the DNS policy.
-
replace\_dns\_header\_field—Checks the opcode type in the DNS request. Returns True or False, indicating whether the opcode type in the DNS request matches the specified opcode type. This action replaces the DNS header section with the defined expression in the DNS policy.
Configuring Rewrite Policies for DNS
Configure Rewrite action and policy, and bind the policy for DNS
-
add rewrite action <actName> <actType>For<actname>, substitute a name for your new action. The name can be 1 to 127 characters in length, and can contain letters, numbers, hyphen (-), and underscore (\_) symbols. For<actType>, specify the rewrite action types provided for DNS expressions. -
add rewrite policy <polName> <rule> <actName>For<polname>, substitute a name for your new policy. For<actname>, the name can be 1 to 127 characters in length, and can contain letters, numbers, hyphen (-), and underscore (\_) symbols. For<actname>, substitute the name of the action that you just created. -
bind rewrite global <polName> <priority> <gotoPriorityExpression> -type <bindPoint>For<polName>, substitute the name of the policy that you just created. For<priority>, specify the priority of the policy. For<bindPoint>, substitute one of the rewrite -specific global bind points.
add rewrite action set_aa replace_dns_header_field dns.req.header.flags.set(aa)
add rewrite policy pol !dns.req.header.flags.is_set(aa) set_aa
bind rewrite global pol 100 -type dns_res_override
add rewrite action set_aa_res replace_dns_header_field "dns.res.header.flags.set(aa)"
add rewrite action modify_nxdomain_res replace_dns_answer_section "dns.new_rrset_a(\"10.102.218.160\",300)"
add rewrite policy set_res_aa true set_aa_res
add add rewrite policy modify_answer "dns.RES.HEADER.RCODE.EQ(nxdomain) && dns.RES.QUESTION.TYPE.EQ(A)"
modify_nxdomain_res
add rewrite policylabel MODIFY_NODATA dns_res
bind rewrite policylabel MODIFY_NODATA modify_answer 10 END
bind rewrite policylabel MODIFY_NODATA set_res_aa 11 END
bind lb vserver v1 -policyName NOPOLICY-REWRITE -priority 11 -gotoPriorityExpression END -type
RESPONSE -invoke policylabel MODIFY_NODATA
-
Rewrite policies are evaluated only if the NetScaler appliance is configured as a DNS proxy server and there is a cache miss.
-
If the Recursion Available (RA) flag in the header is set to YES, the RA flag will not be modified in the rewrites.
-
If the RA flag in the header is set to YES, the CD flag in the header is modified regardless of any rewrite action.