RE: DNS in two domains (one on a DMZ)

From: RyanMac (RyanMac_at_discussions.microsoft.com)
Date: 07/08/04

  • Next message: Phillip Windell: "Re: DNS in two domains (one on a DMZ)"
    Date: Thu, 8 Jul 2004 14:00:01 -0700
    
    

    Rich,
            You may want to check your firewall and make sure port 53 is open both incoming and outgoing.

    "Rich" wrote:

    > I am wondering about the correct DNS settings for a network with two
    > domains.
    > I have an internal domain (DC 172.16.0.1) and a DMZ domain (DC 192.168.0.1).
    >
    > 1. I am going to use ISA server to publish a web server from the DMZ out to
    > the internet. It will access SQL server data on the internal network, which
    > it will access through a publishing rule on the internal ISA server.
    >
    > 2. I would like my internal clients to access the same web server on the
    > DMZ.
    >
    > I have read articles on DNS and DMZs, but am still a little unsure about the
    > exact setup that I need.
    >
    > I started going down the route of assuming I needed to put a forwarder onto
    > my internal DNS server. This should point to a caching server on the DMZ.
    > the caching server should have a forwarder to the internet. I have tried
    > this, but cannot load the stub zone from the master. (I added two server
    > publishing rules for DNS onto the internal server.)
    >
    > Perhaps I have got the wrong end of the stick. Can anyone point me int the
    > right direction?
    >
    > Rich
    >
    >
    >
    >
    >


  • Next message: Phillip Windell: "Re: DNS in two domains (one on a DMZ)"

    Relevant Pages

    • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
      ... NAT, and the DMZ, since it's already secured, is a good place to tack ... If the "company" is not offering services to the Internet, ... and connections to the internal LAN should ... be by means of a second interface on the server. ...
      (comp.security.firewalls)
    • Re: Man gets nine years for spamming
      ... > I don't think we've ever had web access. ... > connect to an inner server where you logged in and actually did stuff. ... We have 12 DMZ interfaces. ... the DMZs and in between the Internet routers and the first ...
      (alt.computer.security)
    • Re: DMZ and file sharing
      ... Never ever use DMZ, a) its an open unlocked door with a big sign saying your ... save/retreive files to/from a restricted area on the LAN. ... and only server. ... You need to consider the safety of the LAN when the web server gets ...
      (microsoft.public.windows.server.sbs)
    • Re: Prividing Intranet Website Access To External Users
      ... I really wouldnt like to be having my company intranet on the ... I would probably integrate the ldap/dc as a security server on the ... >> The web server will be in the DMZ, and only port 443 will be ... >> intranets to the internet in a secure manner. ...
      (Security-Basics)
    • Re: front-end OWA server
      ... The OWA server sits on the DMZ with an internal address off 192.168.100.xxx ... from the internet. ...
      (microsoft.public.exchange.admin)

    Loading