This command performs the following tasks:
- Adds a new DNS Spoof protection IP address
- Deletes an existing DNS Spoof protection IP addresses (IPv4, IPv6, or both) from the Protected Server List (PSL)
- Relists the DNS spoofing protection IP address
This command does not perform when the IPv6 packets have a routing header.
Syntax:
Use the following syntax for adding or deleting a DNS spoof protection IP address:
dnsprotect <add/delete/> <ipv4/ipv6> <IP address>
While using the <resetlist> parameter, use the following syntax:
dnsprotect <resetlist> <ipv4/ipv6/all>
| Parameter | Description |
|---|---|
| add | Adds a new DNS spoofing protection IP address |
| delete | Deletes an existing DNS spoofing protection IP address |
| resetlist | Resets the list the DNS spoofing protection IP address |
| ipv4 | Indicates that the IP address is for IPv4 packet |
| ipv6 | Indicates that the IP address is for IPv6 packet |
| all | Indicates that the resetlist of the existing DNS spoofing protection IP address is for both IPv4 and IPv6 |
| IP address | This is a 32-bit IP address number indicated by four numbers separated by periods (X.X.X.X), where X indicates a number between 0-255. |
Example:
The following example shows the dnsprotect command used for adding the DNS spoof protection IP address for IPv4:
dnsprotect add ipv4 157.125.202.255.
The following example shows the dnsprotect command used for reset listing of DNS spoof protection IP address for all the IP addresses(IPv4 and IPv6):
dnsprotect resetlist all
Applicable to:
NS-series Sensors