Re: Making DNS request to the Internet



In article <Lxvbg.27509$YI5.24041@xxxxxxxxxxxxxxxxxxxxxx>,
Leythos <void@xxxxxxxxxxx> wrote:

In article <1148092604.701427.200080@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
boomboom999@xxxxxxxxx says...
Hi,

Is it considered a good security practice to not allow Active Directory
Domain Controlles making direct DNS requests to the Internet?

I have read about different DNS responses attacks that can help an
attacker to take control of the DC via an incorrect DNS response
(buffer overflow etc.).

Would it be more secure to use DNS forwarders?
If yes, where we should place them? Into DMZ?

If you've got the capital to setup a dedicated DNS server to do the
work, more power to you.

Even if you don't, you can always forward to your ISP's caching servers.

--
Barry Margolin, barmar@xxxxxxxxxxxx
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***
*** PLEASE don't copy me on replies, I'll read them in the group ***
.



Relevant Pages

  • Making DNS request to the Internet
    ... Domain Controlles making direct DNS requests to the Internet? ... I have read about different DNS responses attacks that can help an ...
    (comp.security.misc)
  • Re: DNS as a Generic Cluster Service
    ... I'd rather go with a dedicated DNS server without the ... AD integrated makes ALL the server Primaries for the zones. ... If you could cluster DNS, ...
    (microsoft.public.windows.server.clustering)