All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Shaun T. Erickson" <ste@smxy.org>
To: Netfilter Mailing List <netfilter@lists.netfilter.org>
Subject: OT: split-dns
Date: Tue, 31 Aug 2004 09:34:19 -0400	[thread overview]
Message-ID: <41347E5B.5020401@smxy.org> (raw)
In-Reply-To: <20040831000249.GH20169@metastasis.org.uk>

Nick Drage wrote:
> On Mon, Aug 30, 2004 at 03:23:58PM -0700, Daniel Chemko wrote:
> 
> 
>>>Not knowing what split-dns was, I googled it. If I understand it
>>>correctly it seems that this is only needed when you use a single,
>>>common domain for both internal and external systems. All our
>>>external systems (both between the firewall and the router, and in
>>>the DMZ) are in "domain.com" and all our internal systems are in
>>>"sub.domain.com", so we don't need split-dns, right?
> 
> 
> Probably a good idea anyway - you probably don't want external users
> using your DNS server in the same way that internal hosts do - i.e.
> making recursive lookups.  Also while it isn't much of an information
> leak, stopping Internet users looking up hosts in sub.domain.com won't
> do any harm.

My DNS here is a bit screwy, having inherited it from my predecessor, 
whom I only recently took over for. The outside name server handles our 
primary domain "y.net", only, so external people cannot look up internal 
hosts, but they can make recursive requests for information about our 
external systems. My internal name server handles our internal domain, 
"x.y.net", and a copy of our external domain, on a Windows box. Clients 
are pointed at the internal name server and the secondary nameserver our 
ISP runs for us.

Clearly, this all needs to be re-done, which I plan to do as soon as my 
shiny new server arrives, which I'll migrate all my services too, 
rebuilding them as I go.

> Also with the use of "view" this is pretty easy to do with BIND 9.  If
> you don't have a copy of "DNS and BIND" 

I do - excellent book.

	-ste


      reply	other threads:[~2004-08-31 13:34 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-30 22:23 Need to replace a SonicWall firewall with an iptables firewall Daniel Chemko
2004-08-31  0:02 ` Nick Drage
2004-08-31 13:34   ` Shaun T. Erickson [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=41347E5B.5020401@smxy.org \
    --to=ste@smxy.org \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.