Re: Security on split DNS servers

Tech-Archive recommends: Fix windows errors by optimizing your registry



"Marlon Brown" <MarlonBrown@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:%23s$$ZSVaGHA.4248@xxxxxxxxxxxxxxxxxxxxxxx
I have an existing split DNS configuraiton.
Internal DNS devices serve my AD environmnet.

In the past I heard about additional security configuration I could do in
order to make DNS queries between intenal and external DNS more solid. I
have a firewall between internal and external DNS servers.

There is little or no security for queries in DNS.

There CAN be security for dynamic updates.

Most DNS security is done by POSITIONING the DNS
server within a firewall, or perhaps by having it only
respond to requests on a single NIC if it has more than
one.

If you know what would be a good implementation security wise please let
me know.

Likely you will need to ask a more specific question
for us to give you some idea of your options on that
a specific issue or problem.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


.



Relevant Pages

  • Getting around DNS security hole
    ... find out if your ISP has a DNS security problem. ... basic Internet address system, known as the Domain Name System, is ...
    (soc.retirement)
  • Re: Event ID 5719: No Windows NT or Windows 2000 Domain Controller is available for domain .
    ... In my experience what you have done with security policy should ... The workstation gets its networking information from DHCP that, ... updates DNS. ... I don't believe the problem to be at the server end though. ...
    (microsoft.public.win2000.security)
  • [NT] Vulnerability in DNS Client Allows Spoofing (MS08-020)
    ... Get your security news from a reliable source. ... Vulnerability in DNS Client Allows Spoofing ... This security update resolves a privately reported vulnerability. ... This is an important security update for Windows Vista and all supported ...
    (Securiteam)
  • RE: 2 users 1 workstation
    ... I first checked the DNS forward look up, ... Updated the registry keys for the clients and security policies, ... Migrate-- strBat - [C:\Program Files\Microsoft Windows Small Business ... what it is (i created most of the user accounts of the same way, ...
    (microsoft.public.windows.server.sbs)
  • RE: [fw-wiz] Allowing DNS servers to operate behind NetScreen 500
    ... currently relevant reason for DNS responses to be over 512 bytes in size. ... to a 'proposed standard' RFC and mentioned only DNSSEC as an example, ... use nym-based security, since there isn't any software that supports it. ...
    (Firewall-Wizards)