Re: Multihomed DNS server install problems

From: ObiWan (anzenNO-SPAM_at_gmx.net)
Date: 03/10/04


Date: Wed, 10 Mar 2004 09:31:09 +0100


> > Obiwan,
> >
> > Thanks for the useful information. I am planning on pulling everything
> > private onto a private DNS server and will take your advice.

You're welcome, but I contributed very little here all the "grunt work"
was carried on by Ace and the other folks ... :-)

> > 1) Do I just need to contact my ISP and ask them to include a pointer
> > to my DNS if my reverse resolution is to work. Is that the same as
> > "delegate the IP block"?

As for Ace answer .. yes, that's the usual way to do it, you should
ask them to delegate the reverse zone for your IP block to your
DNS server so that you'll handle the reverse directly from it; btw
be sure to delegate the reverse to both your local (primary) DNS
and a secondary one !!

> > 2) I still get this error when I perform the monitoring test on the
> > DNS. Although everything appears to be working correctly and
> > resolving correctly when I enable the second NIC I get the error. If
> > I disable the second NIC and re-run the test it passes?

> I still think it's due to your binding order and what IP the thing's
> listening on. It makes sense if you run throught what I mean, based on the
> previous post about this.

Yes, it's probably just a matter of NIC/IP binding order, the public NIC
should come first, before the private one, also, be sure that the DNS
machine points to its _public_ address for DNS resolution and not to
its private one; that said, I still prefer (whenever possible) avoiding to
mix/match public and private DNS on the same box; aside from any
config issue, it's a security risk too since an attacker gaining access
to the DNS will be able to see the private addressing scheme and
use it to carry the "penetration" further on, better (as I wrote) using two
separate box and forwarding the private DNS to the public one

<OT>
Ace; did you hear from NT lately ? I think he may have a whole
lot of interesting stuff to talk about and not just about DNS, in
case, just drop him (or me) a line, I think you'll be interested ;-) !
</OT>

-- 
* ObiWan
DNS "fail-safe" for Windows 9x, 2000 and up
http://ntcanuck.com
Support and discussions forum
http://ntcanuck.com/net/board
408 XP/2000 tweaks and tips
http://ntcanuck.com/tq/Tip_Quarry.htm


Relevant Pages

  • Re: DCDIAG DNS Failure
    ... so the sddcsrv03 is a DC and DNS server right? ... also describe your actual reverse ... and forward zones. ...
    (microsoft.public.windows.server.dns)
  • RE: query regarding reverse IP
    ... Generally reverse DNS is governed by your ISP. ... and looking up the PTR record. ... Now when I am searching the other way it is YOUR DNS server that answers ...
    (RedHat)
  • query regarding reverse IP
    ... I am new to DNS concepts.. ... i have a query regarding reverse IP and apprecite if someone could help me... ... i have a DNS server running on xx.xx.xx.1 IP and this DNS server has one domain example.com. ... now i want to know if the reverse lookup can be done locally in my DNS or the ISP. ...
    (RedHat)
  • Re: Multihomed DNS server install problems
    ... > DNS server so that you'll handle the reverse directly from it; ... > be sure to delegate the reverse to both your local DNS ... > NIC should come first, before the private one, also, be sure that the ... Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP ...
    (microsoft.public.win2000.dns)
  • Re: Update dns for local address space
    ... list that as your mailserver, nobody on the internet will know how to ... unless they are also part of your private network. ... reverse lookup on all connections. ... I've never mocked about with DNS in any *nix og *bsd operating systems. ...
    (comp.unix.bsd.freebsd.misc)

Quantcast