Description of the DNS Server Secure Cache Against Pollution setting (316786)
The information in this article applies to:
- Microsoft Windows NT Server 4.0
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Server 2003, Enterprise Edition
This article was previously published under Q316786 SUMMARY
This article provides a description of the DNS Server "Secure cache against pollution" setting. Microsoft DNS server in Windows NT 4.0 and Windows 2000 is capable of cache pollution protection (also called "Secure cache against pollution" or "SecureResponses"). By default, this setting is not enabled in Windows NT 4.0 and pre-Windows 2000 Service Pack 3 (SP3). After you enable this setting, the DNS server ignores DNS resource records that come from servers that are not authoritative for them. Although it can cause extra DNS queries, the security benefits far outweigh the cost of the extra queries, so enabling DNS cache pollution protection is highly recommended.
Modification Type: | Minor | Last Reviewed: | 4/12/2005 |
---|
Keywords: | kbenv kbinfo kbnetwork KB316786 |
---|
|