DNS traffic from DMZ to internal network - Is it vulnerable?

From: Doug Fox (dfox168@hotmail.com)
Date: 11/27/02


From: "Doug Fox" <dfox168@hotmail.com>
Date: Wed, 27 Nov 2002 10:27:23 -0500

A customer has a Check Point FW-1 4.1 SP6 firewall with a DMZ. There is a
requirement for DNS reverse lookup for a server in the DMZ. He wants to
allow DNS (53/udp) traffic from the DMZ to access the internal DNS for
reverse name resolution from the DMZ.

To make this happen, the firewall rule has to allow DNS (53/udp) traffic
from DMZ to the internal network. An opinion against this setup is that it
could allow "intruder" to footprint the internal network?! Is there a way
to mitigate the risk?

Any comments are appreciated.



Relevant Pages

  • Re: Using Microsoft DNS for Public domains
    ... addresses that forward to my two nameserver DNS Servers on my home machine, ... the public IP addresses pointing to the internal DMZ IP addresses. ... >> name I registered two nameservers at my registrar. ... >> the internal DMZ IP of the primary DNS server. ...
    (microsoft.public.windows.server.dns)
  • Re: Domain Controller That Service a DMZ
    ... Where DNS resolution is done, and what resolution path is used, is ... you evidently have machines in that DMZ on which people can ... > for authentication, group policy, etc for the DMZ. ... > the DMZ to be able to use the DMZ domain controller to lookup the DNS ...
    (microsoft.public.windows.server.security)
  • Re: When you run Dcpromo.exe on Windows 2008 to create a replica domain controller, you receive a me
    ... A DMZ is used for servers that are accessed from the outside world with public ip addresses. ... so we can exclude DNS as a problem. ... server has no problem joining the domain. ...
    (microsoft.public.windows.server.active_directory)
  • DNS traffic from DMZ to internal network - Is it vulnerable?
    ... A customer has a Check Point FW-1 4.1 SP6 firewall with a DMZ. ... requirement for DNS reverse lookup for a server in the DMZ. ...
    (comp.security.firewalls)
  • RE: Trusting external domain
    ... allow zone transfers to the IP's on the other domain's DNS servers. ... Create secondary DNS zones in each domain for the other domain (eg: ... down your firewall access from the DMZ to your internal domain). ...
    (microsoft.public.windows.server.active_directory)