109
vpn-instance vpn-instance-name: Specifies an MPLS L3VPN instance by its name, a
case-sensitive string of 1 to 31 characters. To specify a source interface on the public network, do not
use this option.
Usage guidelines
This configuration applies to both IPv4 and IPv6.
In IPv4 DNS, the device uses the primary IPv4 address of the specified source interface as the
source IP address of DNS query.
In IPv6 DNS, the device follows the procedure defined in RFC 3484 to select an IPv6 address of
the source interface as the source IP address for DNS query.
If you use the command multiple times, the most recent configuration takes effect.
You can specify the following:
Source interfaces for the public network and a maximum of 1024 VPNs.
Only one source interface for the public network or each VPN.
Make sure the specified interface is on the VPN specified by the vpn-instance vpn-instance-name
option.
Examples
# Specify VLAN-interface 2 as the source interface for DNS packets on the public network.
<Sysname> system-view
[Sysname] dns source-interface vlan-interface 2
dns spoofing
Use dns spoofing to enable DNS spoofing and specify the IPv4 address to spoof DNS query
requests.
Use undo dns spoofing to disable DNS spoofing.
Syntax
dns spoofing ip-address [ vpn-instance vpn-instance-name ]
undo dns spoofing ip-address [ vpn-instance vpn-instance-name ]
Default
DNS spoofing is disabled.
Views
System view
Predefined user roles
network-admin
Parameters
ip-address: Specifies the IPv4 address used to spoof name query requests.
vpn-instance vpn-instance-name: Specifies the name of an MPLS L3VPN instance, a
case-sensitive string of 1 to 31 characters. To enable DNS spoofing on the public network, do not use
this option.
Usage guidelines
Use the dns spoofing command together with the dns proxy enable command. DNS spoofing
enables the DNS proxy to send a spoofed reply with a configured IP address even if it cannot reach
the DNS server because no dial-up connection is available. Without DNS spoofing, the proxy does