DNS security options
| Security option | Can be applied to all DNS endpoints? | Can be applied to specific DNS virtual servers? |
|---|---|---|
| DNS DDoS protection | Yes | Yes |
| Manage exceptions – whitelist/blacklist servers | Yes | Yes |
| Prevent random subdomain attacks | Yes | Yes |
| Bypass the cache | Yes | No |
| Enforce DNS transactions over TCP | Yes | Yes |
| Provide root details in the DNS response | Yes | No |
| Enforce DNS transactions over TLS | Yes | Yes |
| Enforce DNS transactions over HTTPS | Yes | Yes |
Cache poisoning protection
DNS DDoS protection
-
DROP: - Select this option to DROP requests without logging. Assume that you have enabled A record protection with threshold value 15, time slice as 1 second, and chosen DROP. When the incoming requests exceed 15 queries in 1 second, then the packets start getting dropped.
-
WARN: - Select this option to LOG and DROP requests. Assume that you have enabled A record protection with threshold value 15, time slice as 1 second, and chosen WARN. When the incoming requests exceed 15 queries in 1 second, a warning message is logged indicating a threat and then the packets are dropped. Citrix recommends you to set threshold values for WARN smaller than the threshold value of DROP for a record type. Such a setting helps administrators identify an attack by logging a warning message before the actual attack happens and NetScaler starts dropping incoming requests.
Set a threshold for incoming traffic by using the GUI
-
Navigate to Configuration > Security > DNS Security.
-
On the DNS Security Profile page, click Add.
-
On the Add DNS Security Profile page, do the following:
-
Expand DNS DDoS Protection.
-
Select the record type and enter the threshold limit and the time slice value.
-
Select DROP or WARN.
-
Repeat steps a and b for each of the other record types that you want to protect against.
-
-
Click Submit.
Manage exceptions – allowlist/blocklist servers
-
When a particular IP address is identified posting an attack, such IP address can be added to the block list.
-
When administrators find that there is an unexpectedly high number of requests for a particular domain name, then that domain name can be added to the block list.
-
NXDomainsand some of the existent domains which can consume the server resources can be blacklisted. -
When administrators allow list domain names or IP addresses, queries or requests only from these domains or IP addresses are answered and all others are dropped.
Create an allow list or a block list by using the GUI
-
Navigate to Configuration > Security > DNS Security.
-
On the DNS Security Profiles page, click Add.
-
On the Add DNS Security Profile page, do the following:
-
Expand Manage exceptions – Whitelist/Blacklist Servers.
-
Select Block to block queries from blacklisted domains/addresses, or select Allow only to allow queries from whitelisted domains/addresses.
-
In the Domain name / IP Address box, enter the domain names, IP addresses, or IP address ranges. Use commas to separate the entries. Note: If you select Advanced Option, you can use the "start with," "contains," and "ends with" options to set the criteria. For example, you can set criteria to block a DNS query that starts with "image" or ends with ".co.ru" or contains "mobile sites."
-
-
Click Submit.
Prevent random subdomain attacks
Specify a DNS query length by using the GUI
-
Navigate to Configuration > Security > DNS Security.
-
On the DNS Security Profiles page, click Add.
-
On the Add DNS Security Profile page, do the following:
-
Expand Prevent Random Subdomain Attacks.
-
Enter the numerical value for the query length.
-
-
Click Submit.
Bypassing the cache
Bypass the cache for specified domains or record types or response types by using the GUI
-
Navigate to Configuration > Security > DNS Security.
-
On the DNS Security Profiles page, click Add.
-
On the Add DNS Security Profile page, expand Bypassing the cache and enter the domain names. Optionally, choose the record types or the response types for which the cache has to be bypassed.
-
Click Domains and enter the domain names. Use commas to separate the entries.
-
Click Record Types and choose the record types.
-
Click Response Types and choose the response type.
-
-
Click Submit.
Enforce DNS transactions over TCP
Force domains or record types to operate at the TCP level by using the GUI
-
Navigate to Configuration > Security > DNS Security.
-
On the DNS Security Profiles page, click Add.
-
On the Add DNS Security Profile page, expand Enforce DNS Transactions over TCP and enter the domain names and / or choose the record types for which the DNS transactions must be enforced over TCP.
-
Click Domains and enter the domain names. Use commas to separate the entries.
-
Click Record Types and choose the record types.
-
-
Click Submit.
Provide root details in the DNS response
dnsRootReferral parameter is ENABLED, it exposes all the root servers.
Enable or disable access to the root server by using the GUI
-
Navigate to Configuration > Security > DNS Security.
-
On the DNS Security Profiles page, click Add.
-
On the Add DNS Security Profile page, do the following:
-
Expand Provide Root Details in the DNS Response.
-
Click ON or OFF to allow or restrict access to the root server.
-
-
Click Submit.