Re: DNS traffic from DMZ to internal network - Is it vulnerable?

From: phn@icke-reklam.ipsec.nu
Date: 11/27/02


From: phn@icke-reklam.ipsec.nu
Date: Wed, 27 Nov 2002 19:49:03 +0000 (UTC)

In comp.security.misc Doug Fox <dfox168@hotmail.com> wrote:
> A customer has a Check Point FW-1 4.1 SP6 firewall with a DMZ. There is a
> requirement for DNS reverse lookup for a server in the DMZ. He wants to
> allow DNS (53/udp) traffic from the DMZ to access the internal DNS for
> reverse name resolution from the DMZ.

> To make this happen, the firewall rule has to allow DNS (53/udp) traffic
> from DMZ to the internal network. An opinion against this setup is that it
> could allow "intruder" to footprint the internal network?! Is there a way
> to mitigate the risk?

> Any comments are appreciated.

I suppose internal ip's are rfc1918 networks ?

The most practical way is to have a caching-only server on the DMZ itself,
slaving the 1918 nets from inside.

-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


Relevant Pages

  • RE: [fw-wiz] Backup exec agent in dmz
    ... named.conf file and the zonefiles off the the NT box in the DMZ. ... on the Apache server, ... backup tape library in this DMZ and backup all your servers to the new DMZ. ... what do you really need to back up on the DNS and web servers? ...
    (Firewall-Wizards)
  • Re: Member Server Login Slow DMZ-Internal Subnet
    ... But did I mention that the firewall log showed a successful port 53 ... connection to each DC from the DMZ machine? ... the DMZ machine is the closest AD DC DNS. ... Member Server which was originally installed in the internal subnet ...
    (microsoft.public.win2000.security)
  • Re: DNS ausgehend mit verweigerten Paketen.
    ... Es wird von Extern Port 53 auf intern Port z.B. 4017 verweigert. ... der DMZ nicht stimmt, z.B. falsche Subnetzmaske usw.. ... MVP ISA Server ... Leider funktioniert schon der einfache nslookup bzw. dns request nicht. ...
    (microsoft.public.de.german.isaserver)
  • RE : Securing DNS Server
    ... Your external DNS should not be a secondary of your internal server. ... about the internal AND DMZ server. ... Initially we only had Port 53 Access to this Server from ...
    (Security-Basics)
  • Re: Member Server Login Slow DMZ-Internal Subnet
    ... > connection to each DC from the DMZ machine? ... The only DNS server specified ... > the DMZ machine is the closest AD DC DNS. ... >>> AD across the firewall. ...
    (microsoft.public.win2000.security)