Re: DNS - Firewall

From: Ben Kamen (bkamen-nodamnspam_at_benjammin.net)
Date: 07/20/03

  • Next message: Seb: "[KPF] some rules are deleted at startup"
    Date: Sun, 20 Jul 2003 08:53:54 GMT
    
    

    That's how I do it.

    I know some people have worked out methods for machines with 2 NIC's or 2 IPs to
    do split horizon based on NIC/IP... what a hassle. :)

    Hardware is cheap. :)

    I do the same thing though.

    Ida Young wrote:

    > The firewall should use the internal DNS server if there is so that the
    > firewall can resolv the internal host name and address as well as the
    > external hostname and address.
    >
    > With a firewall, you had better have an internal DNS server and an external
    > DNS server. The internal DNS server resolves the hostnames and IP addresses
    > for your internal machines and firewall. The external DNS server only
    > resolves your public services, and serves for users from Internet.
    >
    > Ida Young
    > Support of ITShield firewall
    > http://www.itshield.com
    >
    >
    >
    > "mike" <m.mike@ny.com> wrote in message
    > news:77a98267.0307140239.250484ed@posting.google.com...
    >
    >>How could I configure the DNS (resolv.conf) in my Firewall? To the
    >>intern DNS in my Lan or extern to my provider?
    >>What's the best and the right way concerning the security and
    >>performance?
    >>
    >>regards,
    >>:-) mike
    >>
    >
    >


  • Next message: Seb: "[KPF] some rules are deleted at startup"

    Relevant Pages

    • Re: DNS - Firewall
      ... > With a firewall, you had better have an internal DNS server and an external ... The internal DNS server resolves the hostnames and IP addresses ... >>intern DNS in my Lan or extern to my provider? ...
      (comp.unix.aix)
    • Re: DNS Weiterleitung "NUR" auf Firewall zulassen
      ... you are using forwarders on your internal DNS ... DNS servers are bypassing your firewall. ... so that queries from the internal DNS server appear to ... und die Fragen zwischen Ihrem internen DNS Bediener und den ...
      (microsoft.public.windows.server.dns)
    • Re: DNS - Firewall
      ... >> intern DNS in my Lan or extern to my provider? ... > The firewall should use the internal DNS server if there is so that the ... you had better have an internal DNS server and an external ...
      (comp.security.firewalls)
    • Re: DNS - Firewall
      ... >> intern DNS in my Lan or extern to my provider? ... > The firewall should use the internal DNS server if there is so that the ... you had better have an internal DNS server and an external ...
      (comp.unix.aix)
    • Re: DNS timeouts?
      ... > I normally just have my internal DNS server forward directly to the ISP. ... This is problematic if the ISA machine is a DOMAIN ... NIC it will override the one from the ISP. ...
      (microsoft.public.win2000.dns)