Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Now on this Windows computer I'm going to change the DNS server to the Cisco Rhoda
so go to the Ethernet settings rather than using Google as the DNS server and CloudFlare.
I'm only going to specify my local reporter as the DNS server now in this example.
I've configured the right to accept a DNS queries and answer them.
And if it doesn't know the answer to forward it to Google this is once again a Cisco broader.
But to your home right it probably does something very very similar.
So if I type show run piping collude which basically allows me to look for a command and search for
DNS you can see that I've enabled IP DNS server so the writer will act like a DNS server show IP right
shows us that it has a default or brought to a router physically in my local network that say another
Cisco rider that actually physically connects me out onto the Internet.
This device can ping Google dot com.
So if I type show run pipe include name typically I would have IP Name Server something like this but
it actually got to that because the outside interface.
In other words the interface connecting this device to the Internet is using DHEA P so through DHEA
P It learnt the default gateway it also learned to the DNS server information.
So once again it could paying David Bumble dot com as an example.
Now the P.C. won't be able to ping right of one dot whom dot com as an example because the broader isn't
configured with that information on the Cisco router if I try and ping rather one dot home dot com that's
not going to work because it doesn't know about that domain.
Notice it's actually trying to get to the Internet right.
To try and find out what did that domain is.
But if I type IP host and specify a hostname like Rod or one home dot com and then specify an IP address
of let's say 10 dot wonder wonder to fly for the local writer this writer will be able to ping itself
it's done a name resolution locally and the P.C. will also be able to ping that domain I'm gonna flush
the DNS cache so it doesn't have any cached entries locally and then ingenious 3 all run a y short capture
here and what we'll filter for is DNS so basically we'll see a DNS request from the P.C. going to the
right and the broader replying if it does a DNS request so ping are one whom dot com that works in why
a shark we can see the DNS request from another random or ephemeral port going to Port 53 but the DNS
server is 10 1 1 2 5 4 which is the local router it's asking for the IP address of this domain name
and the rowdies replying back saying the IP address of that domain name is 10 1 1 2 5 4 so standard
query for an A record because this is IP version 4 but in this case the query went to the broader now
the road is going to forward on DNS queries that it doesn't know the answer to and we can prove that
by running a y shock capture between the broader and the Internet.
So on this link.
So we're seeing a whole bunch of traffic because that is bridge to my physical network.
But once again what I'll do here is filter for DNS can see some other DNS queries are really taking
place.
On the windows P.C. I'll ping David Bumble dot com once again.
You don't have to use ping you could use an as lookup.
So let me show you that as well.
But notice it did get resolved and it looks like it didn't get forwarded
so let's do an honest look up for a different domain.
Let's say Cisco dot com resolution is this IP address so notice.
There we go.
We've done an NSA lookup notice in this case.
It's a DNS query for both the IP version for address.
So we've got a query for the a record Cisco dot com and then we've also got a query for the IP version
6 IP address.
So in this case the reply came back saying this is the IP address of Cisco IP version 4 and this is
the IP version 6 address and we can see that here.
IP version 6 an IP version 4 in our y shock capture notice that the source IP addresses 1 9 2 1 6 8
1 67 which is actually the road show IP interface brief shows us that that is the IP address of the
router so the router is querying another device for the IP address information because it doesn't know
it locally.
So that's the whole idea with DNS.
If the local DNS server doesn't know the answer it forwards that query to a more authoritative DNS server.
And in this case we're getting both the IP version for IP address as well as the IP version 6 IP address
because I used n s lookup.
Now you need to make sure that the DNS server that you querying is giving you good information.
As an example on this broader I could create a hostname for Cisco dot com and simply pointed to another
IP address.
Let's say the local router on the P.C. I'll flush the DNS cache so flush DNS and then I'll ping Cisco
dot com.
Notice the IP address resolved is 10 1 1 2 5 4.
It's not to the actual IP address of Cisco
so if your DNS entries are manipulated or you connecting to a false DNS server you could end up going
to the incorrect server.
You may think you're going to Cisco dot com or another domain but actually you're being redirected somewhere
else.
So hackers will often target the DNS servers have rogue DNS servers which allow them to push your traffic
where they want to.
Again fortunately because of certificates preloaded on browsers today you may be warned if you go to
the wrong server typically you're not going to use your Cisco writer as a DNS server.
You might use it for DNS requests onto a DNS server on the Internet but you wouldn't want to configure
your local broader as the DNS server.
You may in some cases but typically not what you typically want to use is a linux server to be the DNS
server.
So in this example I'm going to show you how to setup a DNS server on a boon to computer.
Now this is a boon to desktop.
Typically you'd run this on a server rather than a desktop.
But the same principle applies.
So I have config shows us the IP address of the server.
Can we ping Google dot com.
Yes we can.
So we getting a resolution of that domain now to set up this boon to P.C. as a DNS server.
I need to disable system D resolved because there's a conflict on Port 53.
You cannot have two services listening on Port 53.
I want to set up DNS mosque.
So I want to disable this process so that DNS mosque can listen on that port number
so I'm going to disable system D result and then I'm going to stop it.
I'll put all these commands below this video if you want to access this yourself and see the commands.
Next thing I'm going to do is edit I'm just going to use nano for that to keep it simple resolve dot
com.
Name Service set to this at the moment.
I'm gonna set the name server to Google
and then I'm going to do sudo apt update to update references.
It might be a bit slow here because I'm going through the genius 3 network going through Cisco devices
like this in Janus 3 is very slow so speed the video up if necessary
OK so the references have been updated.
So what I'm going to do is install DNS mosque
and that's now been installed.
Now my Mac is going crazy.
There seems to be an issue with VMware Fusion and a Mac where the use starts acting like mad.
So I'm sorry if there's a lot of background noise but hopefully you can hear what I'm saying now to
edit DNS mask it's not that difficult.
I'm going to edit it see Dennis mosque conf now quite a few options that you can change here but I'm
just going to change some of the basics.
Set the port to 53 that is the default
for housekeeping and to be a better net citizen.
I'm going to uncommon domain needed and bogus prove.
So we'll never forward plain domain names onto the Internet and non readable address space and then
essentially all I need to do is uncommon at this because I don't want to use Etsy resolve I'm going
to put domain names directly here.
So what I could do is simply add domain names like all one dot home dot com and the IP address and whatever
other domain names I want to enter.
So let's say my broader whom dot com same IP address and then all I need to do is save that file and
then restart the service.
So sudo sys CTO restart DNS mosque
I can look at the status if I want to
can see that this lightweight DHEA P and caching DNS server is running.
So now on my windows P.C. to prove the point let's configure the DNS server to do your boon to P.C.
so I'm gonna set the DNS server here to 200 which is my boon to P.C. click Okay so let's flush the DNS
DNS that's been flushed.
Do that again.
So can I ping R one dot home dot com.
Yes I can because that's been resolved by the ubuntu server.
That was quite a long video but hopefully you've learned something.
I've shown you how to capture DNS queries and responses using Y shock.
I showed you the source and destination port numbers.
I showed you how you can configure a Cisco router as a DNS server and how to configure and a boon to
P.S. as the DNS server.
And then we tested the queries and made sure that it worked properly.
I'm David Bumble and I want to wish you all the very best.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.