Article ID: 934864 - Last Review: December 3, 2007 - Revision: 3.7 How to configure Microsoft DNS and WINS to reserve WPAD registrationOn This PageINTRODUCTIONClient software that is configured to use Web Proxy Automatic Discovery (WPAD) must be able to contact a host that serves a proxy automatic configuration file (Wpad.dat). A WPAD-configured client can use several methods to locate a host that contains a Wpad.dat file. Two of these methods require a WPAD entry to be registered in Domain Name System (DNS) or in Windows Internet Naming Service (WINS). Registering a WPAD entry in DNS or in WINS enables clients to resolve names of hosts that contain proxy automatic configuration files. If an entity can surreptitiously register a WPAD entry in DNS or in WINS, and this entry resolves to a host with a malicious Wpad.dat file, WPAD clients may be able to route their Internet traffic through a malicious proxy server. Network administrators who have not already registered legitimate WPAD entries in DNS or in WINS, and network administrators who have not correctly implemented WPAD through DHCP and Option 252, must reserve static WPAD DNS host names and WPAD WINS name records. By doing this, network administrators help prevent possible malicious registrations. MORE INFORMATIONTo reserve static DNS host names and WINS name records for WPAD, and to reserve other names that you may want to block, follow these steps. DNSTo register a reserved name host entry in DNS, you must register the host name without registering an IP address. Use either of the following methods, as appropriate for your situation.Method 1: Use the DNS Management Console
Method 2: Use commands at a command prompt
WINSTo register a reserved name record in WINS, you must register both the name and the qualified name. (A qualified name is a name that is followed by a period (.) character.) For example, to register the reserved "WPAD" name record in WINS, you must register both of the following names:
WPAD exampleUse the following procedure for the "WPAD" reserved name as a model, and complete the steps for the following items:
APPLIES TO
| Article Translations
|
Back to the top
