Fortinet FortiADC D-Series Handbook

Add to My manuals
470 Pages

advertisement

Fortinet FortiADC D-Series Handbook | Manualzz

Configuring the response rate limit Chapter 6: Global Load Balancing l l l

You must have a good understanding of DNS and knowledge of the DNS deployment in your network.

You must have configured address objects that specify the network segments for which the DNS64 map applies.

See

Configuring an address group

.

You must have Read-Write permission for Global Load Balance settings.

After you have created a DNS64 configuration, you can select it a DNS policy configuration.

To configure DNS64:

1. Go to Global Load Balance > Zone Tools.

2. Click the DNS64 tab.

3. Click Add to display the configuration editor.

4. Complete the configuration as described in

Table 47

.

 Table 47: DNS64 configuration

Settings Guidelines

Name Configuration name. Valid characters are A-Z, a-z, 0-9, _, and -. No spaces. You reference the name in the global DNS policy configuration.

After you initially save the configuration, you cannot edit the name.

IPv6 Prefix

Source

Address

Mapped

Address

IP address and netmask that specify the DNS64 prefix. Compatible IPv6 prefixes have lengths of 32, 40, 48, 56, 64 and 96 as per RFC 6052.

Each DNS64 configuration has one prefix.

Multiple configurations can be defined.

Select an address object. Only clients that match the source IP use the DNS64 lookup table.

Select an address object that specifies the IPv4 addresses that are to be mapped in the corresponding A RR set.

Exclude Select an address object. Allows specification of a list of IPv6 addresses that can be ignored. Typically, you exclude addresses that do have AAAA records.

Configuring the response rate limit

The response rate limit keeps the FortiADC authoritative DNS server from being used in amplifying reflection denial of service (DoS) attacks.

Before you begin: l l

You must have a good understanding of DNS.

You must have Read-Write permission for Global Load Balance settings.

After you have created a response rate limit configuration, you can select it in the DNS policy and DNS general settings configurations.

FortiADC D-Series Handbook

Fortinet Technologies, Inc.

185

advertisement

advertisement

Table of contents