DNS Best Practices

From: Shaun (Shaun_at_discussions.microsoft.com)
Date: 09/22/04


Date: Wed, 22 Sep 2004 13:07:06 -0700

Before we get started let me set the scene. My organization is currently a
Windows NT enviroment but will soon be embarking on Active Directory 2003.
We currently have a DMZ via one-arm routing. We have three web servers in
this DMZ and all are isolated from the internal network. Currently our DNS
is outsourced but we are looking to bring it in house do to some reliability
issues we have been having with our vendor. I am thinking that it would be
best to create a Windows 2003 DNS server in our DMZ for the web servers. On
the internal network install DNS integrated with AD and have the internal
DNS/AD servers foward request for addresses outside of the internal network
to the DNS servers in the DMZ. We are looking at security and preventing
things such as footprinting. I am on the right track here, or is my maddness
flawed? Please advise



Relevant Pages

  • Re: Near and far dmz (is this model secure)
    ... I think that your boss is right, the Exchange servers should be on the ... in a DMZ via VPN tunnel. ... connections from the DMZ to the internal network, ...
    (comp.security.firewalls)
  • Re: Access from DMZ to internal ?
    ... I have a setup with 3 legs - external, DMZ and internal. ... The DMZ╗network has public IP-addresses - the internal network uses ... DNS server can freely access external DNS server), ... between DMZ server and internal server you should create a static NAT ...
    (microsoft.public.isa.configuration)
  • Re: dmz question
    ... >servers in our internal network on the outside of our internal firewall ... EVEN IF IT'S IN A DMZ. ... internal firewall), and access from the DMZ to the world should be limited ... >the outside firewall exposes the internal network). ...
    (comp.security.firewalls)
  • AD DNS stopping problem
    ... there is a DMZ for the external ... the internal network the DNS services on each DC has a record for the address ... of the servers in the DMZ with there IP addresses for the local network (not ... all processors and after something like 10 minutes the DNS service stops. ...
    (microsoft.public.win2000.dns)
  • Access from DMZ to internal ?
    ... I have a setup with 3 legs - external, DMZ and internal. ... The DMZ¨network has public IP-addresses - the internal network uses ... The problem is, that the IP adsress, that the DNS server ... is mapped on the external interface to NAT to 192.168.100.12 ...
    (microsoft.public.isa.configuration)