13.7 Setting Up a DNS Filter

TCP/IP connections to a server can be made by specifying the server's IP address, but most servers, particularly those connected to the Internet, are accessed by their DNS names.

This section contains the following topics:

13.7.1 Setting Up a Stateful DNS Filter

To set up a stateful DNS exception to allow users to use DNS names to connect to servers accessed through the Novell BorderManager server's public interface, complete the following steps from the main FILTCFG menu:

  1. Select Configure TCP/IP Filters, click Packet Forwarding Filters, then click Exceptions.

  2. Press Ins to define a new exception.

  3. Specify the server's private interface for the Source Interface parameter.

  4. Specify the server's public interface for the Destination Interface parameter.

  5. Press Enter for Packet Type, then select dns/udp-st.

  6. Press Esc, select Yes to save the filter.

    IMPORTANT:If applications are configured to use DNS over TCP, you can also configure a stateful DNS exception for DNS over TCP. In Step 5, select the dns/tcp-st packet type instead of the dns/udp-st packet type.

13.7.2 Setting Up Static Filters for DNS

If you do not want to configure a stateful DNS exception, you can create static filters instead.

In the direction that DNS queries will be sent, create the following static packet filter exception:

  • dns/udp

In the direction that DNS responses will be sent, create the following static packet filter exception:

  • dynamic/udp