The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

dnsprotect

Prev Next

This command performs the following tasks:

  • Adds a new DNS Spoof protection IP address

  • Deletes an existing DNS Spoof protection IP addresses (IPv4, IPv6, or both) from the Protected Server List (PSL)

  • Relists the DNS spoofing protection IP address

This command does not perform when the IPv6 packets have a routing header.

Syntax:

Use the following syntax for adding or deleting a DNS spoof protection IP address:

dnsprotect <add/delete/> <ipv4/ipv6> <IP address>

While using the <resetlist> parameter, use the following syntax:

dnsprotect <resetlist> <ipv4/ipv6/all>

Parameter

Description

add

Adds a new DNS spoofing protection IP address

delete

Deletes an existing DNS spoofing protection IP address

resetlist

Resets the list the DNS spoofing protection IP address

ipv4

Indicates that the IP address is for IPv4 packet

ipv6

Indicates that the IP address is for IPv6 packet

all

Indicates that the resetlist of the existing DNS spoofing protection IP address is for both IPv4 and IPv6

IP address

This is a 32-bit IP address number indicated by four numbers separated by periods (X.X.X.X), where X indicates a number between 0-255.

Example:

The following example shows the dnsprotect command used for adding the DNS spoof protection IP address for IPv4:

dnsprotect add ipv4 157.125.202.255.

The following example shows the dnsprotect command used for reset listing of DNS spoof protection IP address for all the IP addresses(IPv4 and IPv6):

dnsprotect resetlist all

Applicable to:

NS-series Sensors