We are a solution provider and the EfficientIP DNS Guardian is one of the products that we offer to our clients.
This product protects against DDoS and DNS flooding.
We recently ran PoC exercises with this product for some of our customers but we are still waiting for their decision on whether they want to implement it. Our client knows that they need it, but don't know how to propose it to management.
You can run a DNS server directly from EfficientIP to help mitigate all DNS attacks from various sources. This is a very good feature.
This product is able to detect bots that have been planted into your network by a hacker. This is an important feature because of the way that some attacks happen these days. For example, a hacker might email an HR person a PDF containing a fictitious CV. Once it is opened, it drops a malicious bot that hibernates. Then at some point, when the hacker wants to freeze your DNS, they activate the bot, and it beings to do damage and steal data.
In standard practice, IT people run a DNS Firewall from a Linux box. This is the most common and it runs using an application called BIND. Microsoft also has a DNS. There are different types of DNS applications being used and one of them is a recursive DNS, whereas the other is non-recursive. The recursive one is more commonly used, and it operates under BIND.
When a hacker attacks the recursive DNS, what EfficientIP does is autorun the non-recursive DNS for the duration of the attack. It can do what is referred to as a master and slave DNS server, where the slave can be attacked but the master still runs. It can even be put into stealth mode. This is a very nice feature.
The point-and-click GUI is very easy to use.