Compared with alternatives, DNSBOX is particularly strong in dealing with the threats to your DDI services.
With most DDI appliance products, you can make your DDI more secure, more reliable and robust by spending more money. With DNSBOX, you can do so while spending less.
DNSBOX has advantages in terms of security and resilience on 2 levels:
|Individual appliances||DDI server architecture|
More secure by design
Easier separation of roles
Network traffic restricted
Easy lower-cost redundancy
Inherently more secure
The DNSBOX platform is particularly secure in general, while the ultra-secure DNSBOX200 – generally deployed in more vulnerable and public-facing roles – features one of the most secure DNS implementations in the world.
DNSBOX uses an orthodox approach to DNS architecture compliant with RFCs, making it easy to put in place multiple layers of protection for maximum security:
- Architectures designed for maximising security, such as:
- Master-slave architecture with master hidden behind firewall.
- Physically isolated recursive and authoritative resolvers.
- Each service runs in its own discrete ‘sandbox’ – secure chroot.
- Affordable separate physical servers for serving different views.
- Security built into core software for each service running on DNSBOX, such as:
- Purpose-built, highly-secure specialist Unbound recursive resolver for DNS caching.
- Security features of BIND.
- DNSSEC to protect against cache poisoning.
- DNSBOX appliances are hardened devices, packed with security features:
- Purpose-built secure Linux Operating System, mounted read-only.
- The ability to separate services and traffic to the appliances onto different IP addresses and multiple different NICs to connect to different networks / users.
- Built in firewall with remote administration only allowed over secure links (SSH / SSL).
- AES encrypted IPsec connections between servers, authenticating and encrypting all traffic between units.
- Routine software updates protect against any security vulnerabilities in embedded software such as BIND. All software on DNSBOX is monitored for security alerts. Any relevant updates are rapidly engineered into DNSBOX and released
More reliable devices, easy redundant architectures
With DNSBOX, you can build more resilient, robust architectures at a lower cost, for 2 reasons:
- An individual DNSBOX appliance is rock-solid:
- It is diskless and uses only solid state storage – making it 10x more reliable. If power fails, there is no loss of data or settings and reboot is immediate.
- DNSBOX’s appliance software is engineered to deal with unexpected network events which can cause servers and services to fail.
- Building redundant architectures is easier and costs less than with alternatives, because of the way the DNSBOX range is designed and priced, with multiple redundancy options