Re: Passing DNS Through DMZ

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: RQ (r.qian_at_inetmail.att.net)
Date: 07/23/04


Date: Fri, 23 Jul 2004 08:49:43 -0500

No, we're using AD DNS. Because the firewall is using NAT, so that users
inside cannot access web site www.company.com . I didn't create a www record
in DNS and use an alias command in firewall.

Roger
"Ace Fekay [MVP]"
<PleaseSubstituteMyActualFirstName&LastNameHere@hotmail.com> wrote in
message news:eDlvjRFcEHA.1248@TK2MSFTNGP11.phx.gbl...
> In news:uWggYS2bEHA.3144@TK2MSFTNGP09.phx.gbl,
> RQ <r.qian@inetmail.att.net> asked for help and I offered my suggestions
> below:
> > I'm using alias command in the firewall to let people access the web
> > sites instead of cteating a new zone in DC.
> >
> > Roger
>
> Sorry, I'm not following what you're implying. Do you mean to say that
your
> internal users are using your firewall as a DNS server?
>
> If that's the case, this is not the method to configure AD and AD clients,
> which of course we know that they must only use the internal DNS. As Jeff
> said, create the zones if not already created, and create a www record and
> give it the internal private IP address. This is of course based on the
fact
> that you are not hosting the zone and their public records and they are
> hosted elsewhere outside.
>
>
> --
> Regards,
> Ace
>
> Please direct all replies ONLY to the Microsoft public newsgroups
> so all can benefit.
>
> This posting is provided "AS-IS" with no warranties or guarantees
> and confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
> Microsoft Windows MVP - Windows Server - Directory Services
>
> Security Is Like An Onion, It Has Layers
> HAM AND EGGS: A day's work for a chicken;
> A lifetime commitment for a pig.
> --
> =================================
>
>



Relevant Pages

  • Re: W2k3 server and DNS
    ... I do not have a Firewall on any of the machines, ... The DNS domain name of AD ... Do the SRV records exist under your zone name? ...
    (microsoft.public.windows.server.dns)
  • Re: Resolving internal and external DNS records
    ... > Our firewall will not allow our internal computers to resolve our external ... > So if my internal users type in www.aaa.com, ... If you don't actually have a Shadow DNS setup then ... you need to add a NEW version of your zone externally. ...
    (microsoft.public.win2000.dns)
  • Re: Update KB951748 causes no connect to internet, anyone have thi
    ... a major snafu from MS to not let firewall makers in on the plan. ... Make sure your DNS and DHCP server IP's are in your Firewall's Trusted zone. ...
    (microsoft.public.windowsxp.network_web)
  • Website setup questions.
    ... Create firewall rule to direct HTTP port 80 to the SBS External NIC ... Create firewall rule to point DNS port 53 to the SBS External NIC ... NICS to get this request to not timeout or be refused. ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... Using ipconfig /all showed the DNS IP is in fact the same IP ... as the firewall as you mentioned. ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)