Educause Security Discussion mailing list archives

Re: Changing ISP?


From: Graham Toal <gtoal () UTPA EDU>
Date: Wed, 4 Oct 2006 13:04:59 -0500

I tried this cheap method with a cable modem connection but I 
got shot down by our DNS administrator.  He said it would not 
work for two reasons.

1. The secondary DNS is actually used heavily even if the 
primary is up.  So it will not work to have your secondary 
DNS offsite and have it resolve your website's address to 
your backup connection.  If you did this lots of folks would 
be directed to your cable modem even if your primary was up.

2. It takes up to 48 hours for all of the Internet DNS 
servers' cache to time out and re-query your DNS server for a 
host name.  Therefore you cannot just have your primary and 
secondary DNS in-sync up until an outage and then edit your 
secondary during the outage to point to your backup.

Do you have a different experience?

No but you have highlighted the points that make the solution
complex.

First of all, you need an offsite DNS which is *normally* feeding
your default zone file as a secondary, but which in time of outage
has to switch to being a primary *but serving a different zone file*.

This is not usually a supported configuration and will rely on various
hacks to watch for connection outages and then switch over the
operating mode.

The second point you made has the consequence that all your DNS tables
have to have a short expiry...

Doable, but hacky and prone to error if say there is a minor netbreak
between your monitor and your home net, which makes it look down when
in fact only a small part of one path is down.

Graham

Current thread: