Re: clients dns settings

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Ace Fekay [MVP]" <PleaseAskMe@xxxxxxxxxxxxxx> wrote in message
news:%23EHgWCvLHHA.4244@xxxxxxxxxxxxxxxxxxxxxxx
Security implications forwarding to an ISP? Some say yes, some say no. I
had
bookmarked an article that argues this, but I can't seem to find it.

I can understand the case where someone would find the ISP
less reliable due to the ISP's security practices than their own.
But for the average small domain admin who doesn't yet fully
understand DNS AND who has a reputable ISP the ISP is likely
to have stronger security than the admin can provide his own
DNS server.

IF the ISP is compromised then your machines could be directed
to "dangerous" partners, e.g., a request for WindowsUpdate.microsoft.com
could return the address of a machine at "evilHackersRUs.com".

If you
are worried about it, as Herb said, you can forward to your router,
provided
it will handle DNS proxy queries that it will forward on to an outside
DNS.

This is MORE secure if the admin has the skills to keep the
machine properly maintained and secured. Lapses here are
still dangerous but not as dangerous as letting a DC or other
critical internal DNS server visit the entire Internet.

Otherwise you can setup and outside DNS server, (which we'll call our "DNS
Resolver") which will use the root hints, and it doesn't have to be a
Windows DNS server, soley for the purpose of forwarding from your internal
DNS.

Here is an NSA Unclassed doc with info on Windows DNS security.

http://www.akomolafe.com/Portals/1/Docs/guide_to_securing_microsoft_windows_2000_dns.pdf

Ace




.



Relevant Pages

  • Getting around DNS security hole
    ... find out if your ISP has a DNS security problem. ... basic Internet address system, known as the Domain Name System, is ...
    (soc.retirement)
  • Re: security based on IP address
    ... I agree with you that your ISP very likely provides an internet protocol ... My cable modem provider required a MAC ... his name with an IP address from security forum posts and IRC chats, ...
    (Security-Basics)
  • RE: Nimda et.al. versus ISP responsibility
    ... The basic Internet user - limited technical expertise, ... manage their own security, with a bit of instruction, and most would be able ... Maybe the answer for the ISP is to assume every customer is in the ... the ISP would assume a higher level of responsibility (but it ...
    (Incidents)
  • Re: Bringing DNS In-house
    ... I would handle all of you internal dns resolutions internally and those addresses that you can't resolve forward to your isp. ... It is a good practice to forward all requests to your isp thereby having the ISP do all the lookup work and not expose your internal ip addresses. ... For failover I have 2 seperate internet feeds with 2 seperate ... ISP (as we use their name servers for our domain name). ...
    (microsoft.public.windows.server.dns)
  • Re: Bringing DNS In-house
    ... I would handle all of you internal dns resolutions internally and those addresses that you can't resolve forward to your isp. ... It is a good practice to forward all requests to your isp thereby having the ISP do all the lookup work and not expose your internal ip addresses. ... For failover I have 2 seperate internet feeds with 2 seperate ... ISP (as we use their name servers for our domain name). ...
    (microsoft.public.windows.server.dns)