Re: DNS on w2k - Internal Only

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Kevin D. Goodknecht Sr. [MVP] (admin_at_nospam.WFTX.US)
Date: 08/06/04


Date: Thu, 5 Aug 2004 20:45:35 -0500

In news:5dde95d2.0408051610.47d67ca8@posting.google.com,
Randy Henson <rhenson@cellxion.com> wrote their comments
Then Kevin replied below:
> forgive me if I seem confused, but with the date/time
> stamp problem mentioned earlier, it looks like you guys
> have responded do my questions before I even see my own
> post.
>
> Setting them up with no gateway I can do. seems that I
> did that before and there was a problem getting to the
> mail server, but that will be another post!

That is why I recommended using a bogus proxy, it still allows OE or Outlook
to access mail servers. If you use web base email you can even set the web
mail name in the bypass proxy list. e.g. *.hotmail.com;*.msn.com in the
bypass proxy list will allow users to get to their hotmail account.

>
> So is it OK that my clients can get out to the net from
> my internal dns server?
That is your decision, there is no technical reason to not allow your DNS to
resolve external names unless it is already over burdened with internal
queries.

I was under the impression that
> there was a way to keep them from going out via the
> internal, and would need to enable forwarders to go out.
> If they can get out via the internal, doesn't that negate
> the need for forwarders???

You enable a forwarder to offload some of the queries to the external DNS
server so it can improve DNS performance. Not enabling the forwarder will
not prevent DNS from resolving names if it can still use its root hints. One
sure fire way to prevent your internal DNS from resolving external names is
to disable recursion on the Advanced tab. That won't prevent determined
users from getting internet access if they want by just putting another DNS
server in TCP/IP properties.

-- 
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
================================================
-- 
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
================================================
http://www.lonestaramerica.com/
================================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
================================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
================================================


Relevant Pages

  • Re: Urgent! New router and big disaster
    ... The SBS DNS server, running on ... its IP it means that your problem is now DNS. ... forward ports to it reliably in the router. ... I should have been more clear about internet connection.. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot connect to RWW from home PC
    ... DNS stuff says your mail server is responding with reply that is not MS ... When we setup this new SBS2003 setup we installed without ISA as it does ... not seeing any problems anywhere regards internet or email - we also run ...
    (microsoft.public.windows.server.sbs)
  • Re: Non-domain connection problem
    ... For some reason the DNS is persistent. ... connect new PC to the internet from the non-domain network: ... In server 2000 gpoedit.msc showed them but in SBS it is different. ...
    (microsoft.public.windows.server.sbs)
  • Re: resolve incorrect IP from RRA server.
    ... dynamic address, 10.5.101.123 from DHCP server. ... This is because the addtional DNS records that get registered cause major problems with AD functionality, especially the additional IPs registered by RRAS. ... However, if you choose to keep RRAS on the DC, then you have to force DNS to only register the internal static interface, and no others. ... If it is the internet gateway, it is recommended to purchase an inexpensive, or cable/DLS router, or even better, a Cisco or similar firewall to perform the task, which if it is compromised by an internet attacker remotely, can further compromise the rest of the internal network. ...
    (microsoft.public.windows.server.dns)
  • Re: Cannot connect to RWW from home PC
    ... DNS stuff says your mail server is responding with reply that is not MS ... When we setup this new SBS2003 setup we installed without ISA as it does ... not seeing any problems anywhere regards internet or email - we also run ...
    (microsoft.public.windows.server.sbs)