Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
PatG
New Contributor

DNS Filter hosted DNS server

I have a split DNS system installed in my network.

 

My external DNS only serves DNS records for my 3 domains.

 

I have been receiving a lot of spurious DNS queries associated with DNS amplification attacks, which all get rejected by bind. However I would like to block these requests at the firewall rather than passing them to my externally facing DNS.

 

So what what I would like to do is:

[ul]
  • Allow queries to:[ul]
  • example1.com
  • example2.com
  • example3.com[/ul]
  • But block queries to any other domain.[/ul]

    Any ideas?

     

    Thanks,

    Pat

  • 1 REPLY 1
    ede_pfau
    SuperUser
    SuperUser

    A custom IPS signature would be an option. No fancy stuff inside, just matching '^(dom1.com|dom2.com|dom3.com)'.

    Actually, you could open a ticket an ask FTNT if they would help out with this.


    Ede

    "Kernel panic: Aiee, killing interrupt handler!"
    Ede"Kernel panic: Aiee, killing interrupt handler!"
    Labels
    Top Kudoed Authors