DNSBOX200 is an advanced DNS slave, recursive resolver (DNS cache) and DHCP server for high performance and security needs. It is a very flexible appliance, which can be licenced for whichever of the 3 services you need and adapts to the specific role(s) to give you a fit-for-purpose device.
|
It can be deployed in different ways:
- Managed seamlessly from the DNSBOX400 / DNSBOX300 master web interface
- Linked to other DNS or DHCP servers
- As a standalone server (DNS cache or DHCP)
In addition, DNSBOX200 can be used as a DNS master, for editing authoritative DNS records. |
DNSBOX200 runs authoritative and recursive (cache) DNS as separate services on the same physical server. This:
- Improves security by isolating the authoritative server from the more vulnerable DNS cache
- Means you can follow this best practice approach yet only need to pay for and manage one physical server – the best of both worlds
- Gives you better performance as specialised software is used for the individual services:
- BIND for authoritative
- Unbound for recursive
When you use the authoritative resolver as a DNS slave…
- You have the specialist DNS admin features you need on a slave:
- Ability to display, filter and search for zones, as well as view their status
- Real-time and historical graphs on performance of your DNS service
- Easy monitoring of slaved zones
- Support for slave and stub zones
- IPv6 support
- Additional features make the service even more secure and reliable:
- Support for DNSSEC signed zones
- TSIG Keys
- IP-secured connections with other DNS servers
- Offline master mode – serving zones from their last known ‘good’ state
Download DNSBOX200‘s factsheet (pdf, 403k)
When you use the recursive resolver (DNS cache)…
- Because the server is Unbound, you get a more secure solution and carrier-grade caching performance – 2.5x performance of BIND
- You have the specialist DNS admin features you need:
- Ability to display, filter, add, edit, delete and search for forward zones
- Automatic forward zones creation for local zones
- Real-time and historical graphs on performance of your DNS service
- Logging recursive queries to syslog and local log
- IPv6 support
- Additional features make the service even more secure and reliable:
- Cache poisoning protection
- DDoS attacks protection
- DNSSEC validation
- High availability load balanced clustering
Download DNSBOX200‘s factsheet (pdf, 403k)
When you use the DHCP Server…
- DHCP configuration is easy and accurate
- Automated validation of DHCP configurations
- Custom configuration fields
- Import/export option for easy backups and ability to copy changes between servers
- Ability to group hosts, subnets and networks
- Support for all DHCPD options
- Ability to assign static IP addresses to clients using MAC authentication
- Automated log rotation
- IPv6 and DHCPv6 support
- You can easily set up DHCP failover to ensure maximum availability
- Single web interface for managing all failover units
- Only the primary needs to be configured
- Automated replication of changes to a secondary active unit
- Informative DHCP statistics give you full visibility of the service. You can:
- View and search for leases
- View and search for hosts, zones, subnets and IP ranges
- Group subnets
- Store additional information about devices
Download DNSBOX200 for DHCP Factsheet (pdf, 945.14kB)
If you have just a few small zones, you can use
DNSBOX
200 as a DNS master for editing authoritative DNS records simply by switching its operating mode from slave to master.
When you use the authoritative resolver as a DNS master…
- You have the specialist DNS admin features you need:
- Ability to display, add, delete, edit, filter and search for zones, as well as view their status
- Real-time and historical graphs on performance of your DNS service
- Easy monitoring of slaved zones
- Support for slave and stub zones
- Automated validation of DNS configuration
- IPv6 support
- Additional features make the service even more secure and reliable:
- Support for DNSSEC signed zones
- TSIG Keys
- IP-secured connections with other DNS servers