Re: DNS Best Practices

From: Todd J Heron (todd_heron_no_spam_at_hotmail.com)
Date: 09/22/04


Date: Wed, 22 Sep 2004 16:21:20 -0400


"Shaun" <Shaun@discussions.microsoft.com> wrote in message
news:8E5718B3-24D6-4F38-810D-7FE7D1AABC42@microsoft.com...
> Before we get started let me set the scene. My organization is currently
a
> Windows NT enviroment but will soon be embarking on Active Directory 2003.
> We currently have a DMZ via one-arm routing. We have three web servers in
> this DMZ and all are isolated from the internal network. Currently our
DNS
> is outsourced but we are looking to bring it in house do to some
reliability
> issues we have been having with our vendor. I am thinking that it would
be
> best to create a Windows 2003 DNS server in our DMZ for the web servers.
On
> the internal network install DNS integrated with AD and have the internal
> DNS/AD servers foward request for addresses outside of the internal
network
> to the DNS servers in the DMZ. We are looking at security and preventing
> things such as footprinting. I am on the right track here, or is my
maddness
> flawed? Please advise

Your plan looks good to me. Forward from your internal AD DNS servers to
the DMZ DNS servers and then forward from your DMZ DNS servers to your ISP
(or straight to the Internet Root servers).

-- 
Todd J Heron, MCSE
Windows 2003/2000/NT


Relevant Pages

  • Re: Forwarding or Stub Zones?
    ... My DMZ has approx 30 servers providing various services. ... internet. ... The servers on the DMZ do not query our ISP they query the DNS servers on ...
    (microsoft.public.win2000.dns)
  • Re: Active Directory and DNS
    ... > All your AD services are registered with DNS. ... >> I have Installed the Windows 2003 Server and configured an Active ... >> to the internet through a linksys firewall/router that does NAT. ... >> Each Windows XP machine is configured with the ISP's dns servers ...
    (microsoft.public.windows.server.active_directory)
  • Re: Split-brain DNS server cannot log into AD domain
    ... >> I have my DNS servers in a split-brain configuration, ... >> name of the Active Directory domain (Windows 2000). ... Internet resolution efficiently. ...
    (microsoft.public.win2000.dns)
  • Re: Conditional recursive DNS - is it possible?
    ... >working as external SMTP server and DNS server for itself, DMZ and internal ... >zone myself on my DMZ DNS servers. ... >for external (Internet) DNS servers to prevent exessive traffic and possible ...
    (microsoft.public.windows.server.dns)
  • Re: Performance problems? 2k dynamic dns issue
    ... Thanks for the Spotlight on windows tip. ... >> to the primary and secondary dns servers we have internally. ... >> person using the internet. ... Download the 30 day trial and ...
    (microsoft.public.win2000.dns)