This command performs the following tasks:
Adds a new DNS Spoof protection IP address
Deletes an existing DNS Spoof protection IP addresses (IPv4, IPv6, or both) from the Protected Server List (PSL)
Relists the DNS spoofing protection IP address
This command does not perform when the IPv6 packets have a routing header.
Syntax:
Use the following syntax for adding or deleting a DNS spoof protection IP address:
dnsprotect <add/delete/> <ipv4/ipv6> <IP address>
While using the <resetlist> parameter, use the following syntax:
dnsprotect <resetlist> <ipv4/ipv6/all>
Parameter | Description |
|---|---|
add | Adds a new DNS spoofing protection IP address |
delete | Deletes an existing DNS spoofing protection IP address |
resetlist | Resets the list the DNS spoofing protection IP address |
ipv4 | Indicates that the IP address is for IPv4 packet |
ipv6 | Indicates that the IP address is for IPv6 packet |
all | Indicates that the resetlist of the existing DNS spoofing protection IP address is for both IPv4 and IPv6 |
IP address | This is a 32-bit IP address number indicated by four numbers separated by periods (X.X.X.X), where X indicates a number between 0-255. |
Example:
The following example shows the dnsprotect command used for adding the DNS spoof protection IP address for IPv4:
dnsprotect add ipv4 157.125.202.255.
The following example shows the dnsprotect command used for reset listing of DNS spoof protection IP address for all the IP addresses(IPv4 and IPv6):
dnsprotect resetlist all
Applicable to:
NS-series Sensors