"DNSBOX has brought tremendous value to our organization. We could easily associate a 7.7€k saving a year"
John Calisi, IT Manager of Operations, Tennessee Board of Regents, USA
"I was the only person who could make changes on our old DNS solution but now customers can manage their own DNS space."
Paul Schuur, Senior Consultant, Qwise BV, Netherlands
"CACHEBOX offered three key criteria in one neat package: enhanced security, increased reliability and ease-of-use"
Mike Bird, IT Director, DHL, UK
"ApplianSys have met all of our requirements as a DNS provider and the platform has provided us with a secure and robust solution"
Karl Jackson, Network Architect, 8el, UK
"Performance is good, support is good and we would recommend ApplianSys and DNSBOX to our own clients."
Paul Schuur, Senior Consultant – Qwise B.V., Holland

Protect Against Cache Poisoning with DNSSEC

Many organisations want to introduce DNSSEC to protect against cache poisoning which can result in your users being misdirected to malicious websites and/or disrupt services that rely on DNS such as email and VOIP.

DNSSEC uses strong public key cryptography to sign DNS data which can then be validated by a requesting server. The root DNS zone and a growing number of Top Level Domains now sign their DNS records using DNSSEC, which creates a ‘chain of trust’ to validate answers down to an individual record. Many ISPs and public DNS services, like Google DNS, can also now carry out this validation process and some governments have required their public sector agencies to implement DNSSEC – for example in the USA.

But… implementing and managing DNSSEC can be complicated, costly and time-consuming:

  • All your zones need to be signed for DNSSEC to be effective – a big task for large networks
  • DNSSEC keys need to be stored securely so that they cannot be changed maliciously
  • Keys also need to be periodically updated – known as ‘key rollover’.
  • Additional DNSSEC steps in DNS resolution may introduce unwanted latency

Automate DNSSEC Key Rollover

DNSSEC-Screenshot-smKey rollover is particularly complex and requires very careful administration. If you get key rollover wrong, keys which are no longer valid remain cached in other DNS servers around the world or are not synchronised with your own upstream servers. In such cases, clients using DNSSEC would be unable to resolve your records.

To avoid this, you need to manage at least two sets of two types of key – a Zone Signing Key (ZSK) and a Key Signing Key (KSK), one of each live and one marked as in ‘rollover state’ – for each zone. The rollover keys need to exist for 2x their Time to Live value. With lots to know and manage, manual key rollover is incredibly error-prone.

You need a solution that, like DNSBOX:

  • Automates DNSSEC key management and rollover
  • Automates zone signing for rapid implementation
  • Makes it easy to store DNSSEC keys securely
  • Uses a high performance resolver to mitigate the extra latency of DNSSEC requests

Next: Microsoft Integration >

Because DNSBOX is versatile and scalable, our customers around the world come in all shapes and sizes. ISPs, enterprises, government agencies and even internet registers simplify, control and protect their DDI services with DNSBOX.

How can we make your visit easier?

Give us a few details about your requirement and we'll make your life easier by serving the most relevant information.
I work in a...
I prefer to read...