Re: DNS best pratice???

From: Herb Martin (news_at_LearnQuick.com)
Date: 12/15/04


Date: Wed, 15 Dec 2004 17:41:13 -0600


"Dan" <Dan@discussions.microsoft.com> wrote in message
news:E2381914-8CD5-4933-A507-94059D1BBC16@microsoft.com...

> Currently my internal DNS servers are forwarding requests to a free bsd
box
> in my DMZ. That system is then forwarding requests to my company's ISP's
DNS
> servers.

That's fine and fairly normal. It offers several
advantages.

> Is there any reason to keep the config this way, or is it better to
> have my internal servers forward requests directly to the ISP's DNS
servers?

It's fine the way it is (if it works for you).

Especially if your inside (BSD) forwarder
has to handle lots of requests OR it's dealing
with a slow WAN line.

> Since my DNS servers are making the original request, I wouldn't have to
> open a port on my firewall would I?

If it is a good firewall and currently properly secured you
would.

> Is there a security benefit in the first scenario that I'm over looking?

Not so much security, since presumably your ISP is
reasonably trustworth, but there is the issue that you
internal DNS (which may even be DCs) don't need
ANY penetration of the (outer) firewall.

It offers some caching benefits with some limited WAN
bandwidth conservation.

It also gives you a place to pull some of the advance
(or goofy) DNS tricks that some of us perform.

The only negative is if the BSD is down, then Internet
resolution fails.

For me this is no problem since my firewall itself (not
a DMS machine) performas this role and so if it is down
nothing goes out that way anyway.

-- 
Herb Martin


Relevant Pages

  • Re: What is this?
    ... >This event is generated when TCP traffic to port 0 is detected. ... This fails on a properly set up firewall. ... accessible DNS servers - one in the DMZ, and two located at our upstream. ... All internal DNS requests go to servers behind the firewall, ...
    (comp.security.firewalls)
  • Re: [PHP] Re: PHP Warning: HTTP request failed -- BSD resource limit reached?
    ... denied their http requests and requests are going to two servers. ... Have you checked your firewall settings? ...
    (php.general)
  • I Need a firewall recommendation.
    ... I Need a firewall recommendation. ... I am setting up two 2003 standard edition web servers. ... Requests for port 80 on the domain domainTest1.com ...
    (comp.security.firewalls)
  • RE: Slow user logon on Terminal server after migration to Windows 2003
    ... The Terminal Servers are 2000 or 2003. ... "Inside the firewall zone" means that the Citrix Servers have a firewall ... available RPC ports? ...
    (microsoft.public.windows.server.active_directory)
  • Re: medical records, web server, & stateful firewall vs packet filter
    ... > image and SQL servers directly (the image server link in particular ... The image and SQL servers ... the 2 firewall layers should run different s/ware - the idea is that a major ... security always cost a lot more than you expect (this comes up whenever we ...
    (comp.dcom.sys.cisco)