Re: dns best security practices

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/25/05


Date: Thu, 24 Mar 2005 22:13:45 -0600

Domain controllers for your network should always be behind your firewall.
Normally a domain controller would never be in a DMZ unless it is a special
situation where it is the domain controller for only DMZ computers. Normally
you only need internal dns servers. Internal dns servers can resolve
internet requests for domain clients if they are configured to use root
hints or forward to your ISP dns server. The main reason you would want an
external dns server is if you are going to host your own dns servers for
your website available for internet users. In such case you would need to
provide two external dns servers. Most however pay a small fee to an ISP to
do this for them. NEVER expose your internal dns servers to internet users.
If your internal users need to access your domain resources on the internet
and you use the same domain name for internet and internal network then you
can use "split brains" dns and add manual records to your internal dns
server for your internal network users to resolve the names of your internet
resources. A Windows dns server does not need to be a domain controller if
you have a need to provide external dns outside of the firewall. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382 --- AD
dns FAQ.

<emmiller@cortdirections.com> wrote in message
news:1111683702.359142.301520@l41g2000cwc.googlegroups.com...
> Where should a server that is a Domain Controller, that also host
> Active Directory and DNS, be placed on a firewall?
>
> What if that server is the external DNS server?
>
> Should a company have both an external and internal DNS server? If so,
> should both of them be Active Directory Domain Controllers?
>



Relevant Pages

  • Help - External DNS & SMTP relay
    ... Only the external DNS server is configured with Internet root hints. ... All internal DNS servers are configured only with the root hints pointing ... Only secure dynamic DNS updates are allowed for all zones except for the ...
    (microsoft.public.security)
  • Re: ISPs DNS as secondary DNS?
    ... I would never recommend setting up ISP's DNS servers in AD environment. ... machines pointing to the domain controller for DNS. ... The most critical server that is used here is across the internet, ...
    (microsoft.public.windows.server.dns)
  • exchange talking to the domain
    ... I just installed Exchange 2007 into my domain with Exchange 2003 and I am ... Event Type: Error ... resource record used to locate a domain controller for domain ... The DNS servers used by this computer for name resolution are not ...
    (microsoft.public.exchange.admin)
  • Re: Windows cannot find the network path error message in GPMC
    ... Preferred DNS server. ... bar of the Network Connections window, ... sure you have Forwarders to your ISP DNS servers Enabled. ... preventing access to this computer from the Internet" is Not checked on this ...
    (microsoft.public.windows.group_policy)
  • Re: Domain Name 2 NS Mapping
    ... On the Public DNS you will create records that have names and IPs to point ... Also if a internet user has to connect to our website ... Internet user's DNS servers will ask the DNS servers listed on your Public ... network, these IPs cannot be routed accross the internet. ...
    (microsoft.public.windows.server.dns)