6. Make DDNS use only secure connections
Many DNS servers accept dynamic updates. The dynamic update feature enables these DNS servers to record the hostname and IP address of a host using DHCP. DDNS can greatly reduce the administrative expenses of DNS administrators, otherwise administrators must manually configure the DNS resource records of these hosts.
However, if the DDNS update is not detected, it may cause serious security problems. A malicious user can configure the host to become a DNS host record that is dynamically updated by a file server, web server, or database server. If someone wants to connect to these servers, they will be transferred to other machines.
You can reduce the risk of malicious DNS upgrades by performing a dynamic upgrade by requiring a secure connection to the DNS server. This is easy to do, you only need to configure your DNS server to use Active Directory Integrated Zones and require a secure dynamic upgrade. In this way, all domain members can update their DNS information securely and dynamically.
7. Disable zone transfer
Zone transfer takes place between the primary DNS server and the secondary DNS server. The primary DNS server authorizes a specific domain name with a rewritable DNS zone file that can be updated as needed. A read-only copy of these zone files is received from the primary DNS server from the DNS server. The DNS server is used to improve the response performance from internal or Internet DNS queries.
However, zone transfers are not just for DNS servers. Anyone who can make a DNS query request may cause a DNS server configuration change that allows zone transfers to dump their own zone database files. Malicious users can use this information to scout naming plans within your organization and attack critical service architectures. You can configure your DNS server, disable zone transfer requests, or allow only zone transfers to specific servers within your organization for security precautions.
8. Use a firewall to control DNS access
A firewall can be used to control who can connect to your DNS server. For DNS servers that only respond to internal user query requests, the firewall should be configured to prevent external hosts from connecting to these DNS servers. For DNS servers that act as cache-only forwarders, the firewall configuration should be set to allow only those query requests from DNS servers that only cache forwarders. An important point in firewall policy settings is to prevent internal users from connecting to external DNS servers using the DNS protocol.
9. Establish access control in the DNS registry
In the Windows-based DNS server, you should set access control in the DNS server-related registry, so that only those accounts that need to be accessed can read or modify These registry settings.
The HKLM\\CurrentControlSet\\Services\\DNS key should only allow access by administrators and system accounts, which should have full control.
10. Setting Access Control in DNS File System Portal
In a Windows-based DNS server, you should set access control at the file system entry of the DNS server so that only the account that needs to be accessed can read or modify these. file.
The %system_directory%\\DNS folder and subfolders should only allow access to the system account, and the system account should have full control. Make DDNS use only secure connections
In the following we will compare these new virtualization products, but we need t
But because of the many similarities between X86 servers and desktops, there are m
As you can see from the prompts, this upgrade will result in the inability to restore the domain to
Website 501 Method Not Implemented Error
Server Security Dog Remote Desktop Protection Tutorial
Resolving data problems Server and storage management
Apache server supports CGI program and SSI program setting method
Five server-based issues that must be understood
Five steps to solve the "server exceeded the maximum allowed connections" error
IIS reported that the script language VBScript.encode error solution was not found on the server
Solve the trouble after the server reinstallation
How to open the Win10 system login information?
Assassin's Creed 1 hidden level how to enter the Assassin's Creed 1 hidden level entry method
How to do not detect the u disk after reloading the win7 system
How to install and run SQL Server 2005 under Win8.1 system
Teach you how to analyze the WLAN netsh command in Windows 7
How does Win10 turn off Windows security alerts?
Win10 right-click menu does not have "graphic properties" and "graphics options" how to do
How to get super administrator rights in Win8 system
Win7 system upgrade to win8.1update graphic tutorial
No need for third-party software to manually build Windows 8 Start Menu