Re: DNS in two domains (one on a DMZ)
From: Phillip Windell (_at_.)
Date: 07/08/04
- Next message: ObiWan: "Re: DNS in two domains (one on a DMZ)"
- Previous message: RyanMac: "RE: DNS in two domains (one on a DMZ)"
- In reply to: Rich: "DNS in two domains (one on a DMZ)"
- Next in thread: ObiWan: "Re: DNS in two domains (one on a DMZ)"
- Reply: ObiWan: "Re: DNS in two domains (one on a DMZ)"
- Messages sorted by: [ date ] [ thread ]
Date: Thu, 8 Jul 2004 16:34:30 -0500
"Rich" <RWad@RWcom> wrote in message
news:uRevrsQZEHA.2816@TK2MSFTNGP11.phx.gbl...
> I am wondering about the correct DNS settings for a network with two
> domains.
> I have an internal domain (DC 172.16.0.1) and a DMZ domain (DC
192.168.0.1).
>
> 1. I am going to use ISA server to publish a web server from the DMZ out
to
> the internet. It will access SQL server data on the internal network,
which
> it will access through a publishing rule on the internal ISA server.
That depends on *which* ISA on what *kind* of DMZ.
Here are that variations, and each is handled differently
1. Back-to-Back with 2 ISA's (one on each end)
2. Back-to-Back with 2 firewalls (one on each end, no ISA)
3. Back-to-Back with 1 ISA, 1 firewall (firewall on Internet end)
4. Back-to-Back with 1 ISA, 1 firewall (ISA on Internet end)
5. Tri-Homed DMZ using a firewall (no ISA)
6. Tri-Homed DMZ using a ISA (no hardware firewall)
Then just for fun you can have a Back-toBack and a Tri-Homed at the same
time using any combination of the above which brings you up to about 14
different types of DMZs
> I started going down the route of assuming I needed to put a forwarder
onto
> my internal DNS server. This should point to a caching server on the DMZ.
> ................
> this, but cannot load the stub zone from the master. (I added two server
> publishing rules for DNS onto the internal server.)
You don't "publish" any DNS.
All clients point to the Internal DNS, it is turn uses a Forwarder to the
DNS on the DMZ, which in turn uses a Forwarder to the ISP's DNS.
That is the best I can tell you with something like this. If I was in that
position I would go way, way, out of my way to create a simpler situation.
-- Phillip Windell [MCP, MVP, CCNA] www.wandtv.com
- Next message: ObiWan: "Re: DNS in two domains (one on a DMZ)"
- Previous message: RyanMac: "RE: DNS in two domains (one on a DMZ)"
- In reply to: Rich: "DNS in two domains (one on a DMZ)"
- Next in thread: ObiWan: "Re: DNS in two domains (one on a DMZ)"
- Reply: ObiWan: "Re: DNS in two domains (one on a DMZ)"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|