Mitigate DNS DDoS attacks
-
Flush negative records.
-
Restrict the time to live (TTL) of negative records.
-
Preserve NetScaler memory by limiting the memory consumed by the DNS cache.
-
Retain DNS records in the cache.
-
Enable DNS cache bypass.
Flush negative records
Flush negative cache records by using the CLI
flush dns proxyrecords -type (dnsRecordType | negRecType) NXDOMAIN | NODATA
flush dns proxyrecords –negRecType NODATA
Flush of negative cache records by using the GUI
-
Navigate to Configuration > Traffic Management > DNS > Records.
-
In the details pane, click Flush Proxy Records.
-
In the Flush Type box, select Negative Records.
-
In the Negative Records Type box, select either NXDOMAIN or NODATA.
Protection against random subdomain and NXDOMAIN attacks
-
This limitation is added per packet engine. For example, if the maxCacheSize is set to 5 MB and the appliance has 3 packet engines, the total cache size is 15 MB.
-
The cache size for the negative records must be less than or equal to the maximum cache size.
-
If you reduce the DNS cache memory limit to a value lower than the amount of data already cached, the cache size remains above the limit until the data ages out. That is, exceeds its TTL0 or is flushed (
flush dns proxyrecordscommand, or Flush Proxy Records in the NetScaler GUI). -
To configure SNMP traps, see Configuring the NetScaler to Generate SNMP Traps.
Limit the memory consumed by the DNS Cache by using the CLI
set dns parameter -maxCacheSize <MBytes> -maxNegativeCacheSize <MBytes>
set dns parameter - maxCacheSize 100 -maxNegativeCacheSize 25
Limit the memory consumed by the DNS Cache by using the GUI
-
Max Cache Size in MB
-
Max Negative Cache Size in MB
Restrict the TTL of negative records by using the CLI
set dns parameter -maxnegcacheTTL <secs>
set dns parameter -maxnegcacheTTL 360
Restrict the TTL of negative records by using the GUI
-
Navigate to Configuration > Traffic Management > DNS.
-
Click Change DNS Settings and set the Max Negative Cache TTL in sec parameter.
Retain DNS records in the cache
-
This option can be used only when the maximum cache size is specified (maxCacheSize parameter).
-
If maxnegcacheTTL is configured and cacheNoExpire is enabled, cacheNoExpire takes priority.
Retain DNS records in the cache by using the CLI
set dns parameter -cacheNoExpire ( ENABLED | DISABLED)
set dns parameter -cacheNoExpire ENABLED
Retain DNS records in the cache by using the GUI
-
Navigate to Configuration > Traffic Management > DNS and click Change DNS Settings.
-
Select Cache No Expire.
Enable DNS cache bypass
Enable DNS cache bypass by using the CLI
set dns parameter -cacheHitBypass ( ENABLED | DISABLED )
set dns parameter -cacheHitBypass ENABLED
Enable DNS cache bypass by using the GUI
-
Navigate to Configuration > Traffic Management > DNS and click Change DNS Settings.
-
Select Cache Hit Bypass.
Prevent the Slowloris attack
Slowloris attack. The NetScaler appliance can silently drop DNS queries that are split into multiple packets.
splitPktQueryProcessing parameter to ALLOW or DROP a DNS query if the query is split into multiple packets.
Limit the DNS queries to a single packet by using the CLI
set dns parameter -splitPktQueryProcessing ( ALLOW | DROP )
set dns parameter -splitPktQueryProcessing DROP
Limit DNS queries to a single packet by using the GUI
-
Navigate to Configuration > Traffic Management > DNS and click Change DNS Settings.
-
In the Split Packet Query Processing box, choose ALLOW or DROP.
Collect statistics of the DNS responses served from the cache
stat lb vserver <DNSvirtualServerName> command:
-
Requests – Total number of requests received by the DNS or DNS_TCP virtual server. Includes the requests forwarded to the back end and the requests answered from the cache.
-
Vserver hits –Total number of requests forwarded to the back end. The number of requests served from the cache is the difference between the total number of requests and the number of requests served from the virtual server.
-
Responses – Total number of responses sent by this virtual server. For example, if a DNS LB virtual server received 5 DNS requests, forwarded 3 of them to the back end, and served 2 of them from the cache, the corresponding value of each of these statistics would be as follows:
-
Vserver hits: 3
-
Requests: 5
-
Responses: 5
-
Enable DNS root referral
Enable root referral by using the CLI
- set dns parameter -dnsrootReferral ENABLED
- show dns parameter
> set dns parameter -recursion ENABLED
Done
> show dns parameter
DNS parameters:
.
.
.
DNS Root Referral : ENABLED
.
.
.
Done
Enable root referral by using the GUI
-
Navigate to Traffic Management > DNS.
-
In the details pane, under Settings, click Change DNS settings.
-
In the Configure DNS Parameters dialog box, select the Enable Root Referral checkbox, and then click OK.