Re: [fw-wiz] DNS records for a firewall NAT pool

From: R. DuFresne (dufresne_at_sysinfo.com)
Date: 07/29/03

  • Next message: Noonan, Wesley: "RE: [fw-wiz] Off topic: Any one know of a good IPV6 reference boo k?"
    To: "Pollock, Joseph" <PollockJ@evergreen.edu>
    Date: Tue, 29 Jul 2003 13:37:41 -0400 (EDT)
    
    

    could not the fix for this client be a hardcoded hosts file?

    I've not mucked about alot with tcpd and compiling lately with the
    paranoid switches, but, this might be the way to do this 'quetly", of
    course resolv.conf need to point to files first on this system.

    Thanks,

    Ron DuFresne

    On Mon, 28 Jul 2003, Pollock, Joseph wrote:

    > What DNS records are appropriate for addresses in a firewall NAT pool?
    >
    > We have long provided dummy PTR records for the addresses to deal with
    > software that does a reverse lookup. We have not configured matching A
    > records, feeling it was inappropriate and likely in conflict with, for
    > example, RFC 2182, since the hosts are not directly reachable.
    >
    > We are suddenly faced with a researcher who cannot connect to a well-known
    > database. The site tells me they use TCPWrappers in a manner that requires
    > matching forward and reverse lookups to pass the connection on to the
    > server.
    >
    > We could, of course, configure a static NAT entry for the two hosts
    > required; my management prefers to not do this for a variety of reasons.
    >
    > What are the implications of populating our DNS server with matching dummy A
    > records for all of our firewall pool?
    >
    > Joe Pollock
    > Network Services
    > The Evergreen State College
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    >

    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            admin & senior security consultant:  sysinfo.com
                            http://sysinfo.com
    "Cutting the space budget really restores my faith in humanity.  It
    eliminates dreams, goals, and ideals and lets us get straight to the
    business of hate, debauchery, and self-annihilation."
                    -- Johnny Hart
    testing, only testing, and damn good at it too!
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Noonan, Wesley: "RE: [fw-wiz] Off topic: Any one know of a good IPV6 reference boo k?"

    Relevant Pages

    • Re: [fw-wiz] DNS records for a firewall NAT pool
      ... I can't think of any negative implications of point names at those addresses. ... > example, RFC 2182, since the hosts are not directly reachable. ... > matching forward and reverse lookups to pass the connection on to the ... > What are the implications of populating our DNS server with matching dummy A ...
      (Firewall-Wizards)
    • Re: IPS comparison
      ... > my DNS server starts to connect to all the other hosts on my network, ... When a new DNS server comes online, ... Workstation-A has 2 nameservers configured, ...
      (Focus-IDS)
    • Re: Ping returns the wrong name; nslookup OK
      ... My internal dns server has the internal ip address for the host, and the external dns A record is hosted in the cloud. ... There isn't a hosts table entry - I've had to add one to force the internal IP to resolve correctly. ... In discussion with a colleague in the office, I added a stub zone to a primary on the main internal dns server, the re-tried the lookup again. ... Once you've made a reference to it, then it can resolve it, otherwise it would use it's general forwarder or the Root hints. ...
      (microsoft.public.windows.server.dns)
    • Re: Curious DNS traffic
      ... I'm seeing strange DNS traffic from one of my windows hosts. ... attmepting to communicate to external hosts on port 53. ... The target hosts is a root server in the Netherlands so it appears ... it queries the local DNS server while continuing ...
      (microsoft.public.security)
    • Re: How big can HOSTS be?
      ... To translate from the URL that you type in your browser to ... The URL is looked up there and the DNS server ... The Hosts file essentially asks like a local DNS server for web sites ... Secondarily, the Hosts file can be used to block addresses, but that's ...
      (microsoft.public.windowsxp.general)

  • Quantcast