Firewall Wizards mailing list archives

Re: DNS behind a firewall with multiple domains?


From: Joseph S D Yao <jsdy () cospo osis gov>
Date: Mon, 15 Mar 1999 13:40:47 -0500 (EST)

I'm not sure if I read the desciption of your problem correctly.  I get
the impression that you have multiple internal DNS's and need to
resolve all internal queries.

Why not set up another DNS server and make it secondary to all
of the internal DNS's.  This way you'll have a central point that
you can query for all of your internal hosts.

Tim Kramer
tkramer () irt net

An interesting idea, and one that somebody else suggested privately.
I'm thinking about whether this is doable.  Previously, somebody had
tried a "universal secondary", but it got stale and corrupted the DNS
supply - sites were getting new designated baby seals that didn't know
to update serial numbers when they updated their DNS.  If this
psychsocial problem could be overcome, perhaps this would be the
easiest way to go.  [We also have to think about what's maintainable
for the vendor.  ;-(]

Thanks.

--
Joe Yao                         jsdy () cospo osis gov - Joseph S. D. Yao
COSPO/OSIS Computer Support                                     EMT-A/B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.



Current thread: