cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
452
Views
0
Helpful
1
Replies

Cache pollution on DNS servers

5creedus
Level 1
Level 1

looking for the sigID that would fire on this. We are running 4.1(5)S216.

1 Reply 1

wsulym
Cisco Employee
Cisco Employee

In the general sense of cache pollution (cache poisoning) - DNS responses contain additional records that do not pertain to the query in an effort to poison the DNS server's cache. No, there is no signature for this.

I know Microsoft has a "cache pollution protection" knob on their DNS servers and recent versions of BIND also contain code to perform some additional checks and ignore the non-relevant responses.

Review Cisco Networking for a $25 gift card