dns-redirect

Function

The dns-redirect command redirects DNS packets to a web server address.

The undo dns-redirect command cancels the configuration.

By default, the function to redirect DNS packets to a web server address is not configured.

This command is supported only on the NetEngine 8000 F1A.

Format

dns-redirect

undo dns-redirect

Parameters

None

Views

Traffic behavior view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
portal write

Usage Guidelines

Usage Scenario

When users access web services using HTTPS, the system checks the DNS packets to be sent to a pre-authentication domain against a whitelist. If you want the system to redirect the DNS packets that do not match the whitelist, run the dns-redirect command to set a web server address.

The web server address forcibly pushed to users is configured in the user online domain.

Prerequisites

  • Basic configurations for login have been complete. The web server address forcibly pushed to users has been configured in the user online domain.
  • The UCL-based traffic classification profile, traffic behavior profile, and traffic policy profile have been configured in the system view.

Precautions

This command is supported only on the admin VS.

The dns-redirect command is mutually exclusive with the following commands:

  • http-redirect
  • http-redirect plus
  • redirect-cpu http-redirect-chasten
  • redirect-cpu portal

Example

# Redirect DNS packets to the web server address.
<HUAWEI> system-view
[~HUAWEI] traffic behavior behavior1
[~HUAWEI-behavior-behavior1] dns-redirect
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >