DNS Mapping on NGAF

rohmattullah Lv1Posted 2024-Jul-30 20:16

What is the function of "DNS Mapping" in NGAF? Are there any best practices for using this tool?

Newbie517762 has solved this question and earned 20 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

HiHi,

DNS mapping enables LAN users to access LAN servers through the domain names of the public network. This achieves the same effect as the bidirectional NAT policy.
After DNS mapping is set, when a LAN user sends the DNS request, the NGAF device actively resolves the domain name into the LAN IP address of the server and returns it to the client. The client directly accesses the LAN IP address of the server without policy-based translation.

Please find the attached file for DNS-Mapping Configuration Example.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Is this answer helpful?
juni Posted 2024-Jul-30 21:06
  
hello.
DNS mapping on a Next-Generation Application Firewall (NGAF) involves configuring the firewall to interpret and manage DNS queries to ensure secure and optimized traffic handling. Here’s an overview of the process:

### Key Concepts of DNS Mapping on NGAF

1. **DNS Security**: NGAFs can provide DNS filtering to block malicious domains and prevent users from accessing harmful websites.

2. **Domain Whitelisting/Blacklisting**: Administrators can configure the NGAF to allow or deny traffic based on specific domains, enhancing security.

3. **Traffic Inspection**: NGAFs can inspect DNS traffic to identify and mitigate threats, such as DNS tunneling, which can be used to exfiltrate data.

4. **DNS Logging**: The NGAF can log DNS queries and responses, providing visibility into domain resolutions and potential security incidents.

5. **Integration with Threat Intelligence**: Many NGAFs can integrate with threat intelligence feeds to automatically update domain blacklists, ensuring that emerging threats are blocked in real-time.

### Steps to Configure DNS Mapping on NGAF

1. **Access the NGAF Management Interface**:
   - Log in to the management console of your NGAF.

2. **Configure DNS Settings**:
   - Navigate to the DNS settings section.
   - Set up primary and secondary DNS servers that the NGAF will use for resolution.

3. **Enable DNS Inspection**:
   - Turn on DNS traffic inspection features to allow the firewall to analyze DNS packets for anomalies and threats.

4. **Create Domain Policies**:
   - Define policies for domain whitelisting and blacklisting based on organizational needs.
   - Set up rules for blocking or allowing specific domains or domain categories.

5. **Set Up Logging and Alerts**:
   - Enable logging for DNS queries to monitor access patterns and potential threats.
   - Configure alerts for suspicious DNS activity, such as requests to known malicious domains.

6. **Integrate Threat Intelligence**:
   - If available, integrate external threat intelligence feeds to keep your DNS filtering policies up-to-date with emerging threats.

7. **Testing and Validation**:
   - Test the configuration by attempting to access whitelisted and blacklisted domains to ensure the rules are functioning as intended.
   - Validate that logs are being generated as expected.

8. **Ongoing Maintenance**:
   - Regularly review DNS policies and logs to adapt to new threats and changes in your network environment.

### Conclusion

Implementing DNS mapping on an NGAF enhances your organization's security posture by providing robust controls over DNS traffic. Regular updates and monitoring are essential to maintain the effectiveness of these configurations against evolving threats.
Enrico Vanzetto Lv4Posted 2024-Jul-30 21:42
  
Hi, on Sangfor' s NGAF, the DNS Mapping function maps domain names to IP addresses, helping administrators manage network traffic efficiently. It aids in load balancing, enhances security by redirecting traffic, and simplifies network management by using domain names instead of IP addresses
Newbie517762 Lv5Posted 2024-Jul-31 09:24
  
HiHi,

DNS mapping enables LAN users to access LAN servers through the domain names of the public network. This achieves the same effect as the bidirectional NAT policy.
After DNS mapping is set, when a LAN user sends the DNS request, the NGAF device actively resolves the domain name into the LAN IP address of the server and returns it to the client. The client directly accesses the LAN IP address of the server without policy-based translation.

Please find the attached file for DNS-Mapping Configuration Example.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
fuadmahbubun Lv2Posted 2024-Jul-31 09:56
  
DNS mapping almost same function as static dns, you can set NGAF as DNS server then configure the domain name and ip address.
you may refer to this guidance :

https://knowledgebase.sangfor.com/detailPage?articleData=%7B%22articleType%22%3A1,%22articleId%22%3A%221dbaba2ee0ac458ba32680f5e42bc770%22,%22keyword%22%3A%22%22%7D


Farina Ahmed Lv5Posted 2024-Jul-31 14:12
  
The "DNS Mapping" function in NGAF (Next-Generation Application Firewall) allows administrators to create custom DNS entries that can redirect requests to specific IP addresses. This feature can be used to manage and control access to various services, enhance security by preventing access to malicious domains, and improve network efficiency by optimizing the resolution of frequently accessed domains. Best practices for using DNS Mapping include regularly updating the DNS entries to reflect changes in the network infrastructure, ensuring that mappings do not conflict with external DNS records, and using it to block access to known malicious or unwanted sites.

I Can Help:

Change

Moderator on This Board

11
8
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
138
3

Started Topics

Followers

Follow

Board Leaders