In this task, you create a DNS security profile and configure DNS security settings at the
same time. However, you can also configure settings in a DNS security profile that already
exists.
The BIG-IP® system can allow or drop packets of specific DNS
query types, or with specific opcodes, to prevent attacks or allow legitimate DNS
traffic. Use this to filter out header opcodes or query types that are not necessary on
your system, or to respond to suspicious increases in packets of a certain type, as
identified with the DNS security profile.
-
On the Main tab, click .
The DNS Security Profiles list screen opens.
-
Click Create.
The Create New DoS Profile screen opens.
-
In the Profile Name field, type the name for the
profile.
-
From the Query Type list, select how to handle query
types you add to the Active list.
- Select Inclusion to allow packets with the DNS
query types you add to the Active list, and drop all
others.
- Select Exclusion to deny packets with the DNS
query types you add to the Active list, and allow all
others.
-
In the Profile Name field, type the name for the
profile.
-
In the Profile Name field, type the name for the
profile.
-
In the Profile Name field, type the name for the
profile.
-
Click Update to save your changes.
Now you have configured the profile to include or exclude only specified DNS query
types and header opcodes.
Specify this DNS security profile in a local traffic DNS profile attached to a
virtual server.