- play_arrow Set Up
- play_arrow Juniper Advanced Threat Prevention Cloud Overview
- play_arrow Enroll SRX Series Firewalls to Juniper Advanced Threat Prevention Cloud
- play_arrow Configure Security Policies on SRX Series Firewall
- play_arrow Configure SRX Series Firewall
- Configure the SRX Series Firewall to Block Outbound Requests to a C&C Host
- Configure the SRX Series Firewall to Block Infected Hosts
- Configure Reverse Proxy on the SRX Series Firewall
- Configure the IMAP Emails Policy on the SRX Series Firewall
- Configure the SMTP Emails Policy on the SRX Series Firewall
-
- play_arrow Configuration Statements and Operational Commands
- play_arrow SRX Series Firewall Commands to Configure Juniper ATP Cloud
-
- play_arrow Use Cases
- play_arrow SecIntel Feeds for MX Series Routers
- play_arrow Amazon Web Services GuardDuty with vSRX Virtual Firewall
- play_arrow Juniper ATP Cloud with Policy Enforcer
-
- play_arrow Troubleshoot
- Juniper ATP Cloud Troubleshooting Overview
- Troubleshooting Juniper ATP Cloud: Checking DNS and Routing Configurations
- Troubleshooting Juniper ATP Cloud: Checking Certificates
- Troubleshooting Juniper ATP Cloud: Checking the Routing Engine Status
- Troubleshooting Juniper ATP Cloud: Checking the Application-Identification License
- Viewing Juniper ATP Cloud System Log Messages
- Configure Traceoptions
- View the Traceoptions Log File
- Turning Off Traceoptions
- Juniper ATP Cloud Dashboard Reports Not Displaying
- Juniper ATP Cloud RMA Process
- play_arrow More Documentation
- play_arrow Additional Documentation on Juniper.net
-
DNS Tunnel Detection Overview
DNS Tunneling is a cyber-attack method that encodes the data of other programs or protocols in DNS queries and responses. It indicates that DNS traffic is likely to be subverted to transmit data of another protocol or malware beaconing.
When a DNS packet is detected as tunneled, the SRX Series Firewall can take permit, deny or sinkhole action.
DNS Tunneling detection is available only with Juniper ATP Cloud license. For feature specific licensing information, see Software Licenses for ATP Cloud.
SRX Series Firewall exports the tunneling metadata to Juniper ATP Cloud. To view the DNS tunneling detections, log in to Juniper ATP Cloud Web portal and navigate to Monitor > DNS. Click on the Tunnel tab to view the DNS tunnel detections as shown inFigure 1 . You can click on a domain name to view more details of the hosts that have contacted the domain.

DNS Tunneling Procedure
Here's how DNS tunneling works:
- A cyber attacker registers a malicious domain, for example, “badsite.com”.
- The domain’s name server points to the attacker’s server, where DNS Tunneling malware program is running.
- DNS Tunnel client program running on the infected host generates DNS requests to the malicious domain.
- DNS resolver routes the query to the attacker’s command-and-control server.
- Connection is established between victim and attacker through DNS resolver.
- This tunnel can be used to exfiltrate data or for other malicious purposes.