Re: Client resolution of internet names



In general, if you have invested in a proxy server then you should
use it. Bypassing it only reduces the values it can provide to you.

Having a DNS server forward queries to external DNS servers
does not reveal internal information. Allowing the public NIC
interface used for the DNS forwarding to also respond to DNS
queries received on it however can. These are two separate
capabilities and are configured independently from each other.

"jamestulloch" <james@xxxxxxxxxxxxxxxx> wrote in message
news:1167305112.501222.155390@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi All,

Should I allow clients to resolve internet adresses by setting up
forwarding on my DNS servers. All my DNS servers are DCs in Windows
2003 native domain.

I was going to just force all internet lookups to go via IE and proxy
server.

What are the security implications of allowing this. I read somewhere
that the DNS acket will contain information about the ip address
structure and naming of our domain. Is this true? Does it matter?

TIA

James Tulloch



.



Relevant Pages

  • Re: AD Replication: What Does "Fully Routed" Mean?
    ... pointing to two DNS servers could cause problems for Active Directory. ... have the server down for maintenance, as it stands now, I can't resolve ... names without having the second DNS server in my NIC's config, ... > settings (if you resolve the Internet and are not using the more ...
    (microsoft.public.win2000.active_directory)
  • Re: VPN Setup
    ... the 'internet' NIC be one off from the router's LAN IP or its WAN IP address? ... > only an internal DNS Server hosting the zone name for the Active Directory ... > The only place ISP DNS servers belongs in the network is under your DNS ... > clients, to include DNS servers. ...
    (microsoft.public.windows.server.general)
  • Re: Win Server 2003 -- 0x80072F78
    ... Service Pack 1 of Windows Server 2003, the technology used to deliver updates ... You do not know the proxy server name or its IP address and/or ... You cannot find the above items specified in the LAN Settings of the Internet ...
    (microsoft.public.windowsupdate)
  • Re: VPN Setup
    ... The Ip of the 'internet' ... network card should be one off from the DSL router. ... only an internal DNS Server hosting the zone name for the Active Directory ... The only place ISP DNS servers belongs in the network is under your DNS ...
    (microsoft.public.windows.server.general)
  • Re: Secondary Zones All Stopped Working - Win2003
    ... The two DNS servers need to have separate zones, ... >> Secondary servers are also needed for your public facing DNS server, ... It does if Internet users can't send you mail because your primary is ...
    (microsoft.public.windows.server.dns)