What does "Forward lookup to validate qualified DNS" do?


This article applies to:

  • R3000

Question:

What does "Forward lookup to validate qualified DNS" do?

Reply

In filter version 2.0.10.8, a new option was added to the medium HTTPS filtering level, and this option is enabled by default.  This option is a checkbox for "Forward lookup to validate qualified DNS."  Ordinarily, on the medium HTTPS filtering level, the URL of an HTTPS site is found by looking up the hostname on the site's SSL certificate.  If the forward lookup option is enabled, the filter will also perform a DNS lookup on the hostname that it finds, and the site will be blocked if the IP returned from the DNS lookup differs from the IP of the site being accessed.
This article was previously published as:
8e6 KB 282670

Last Modified 4/10/2008.
https://support.trustwave.com/kb/KnowledgebaseArticle12479.aspx