Firewall Wizards mailing list archives

Re: Split DNS, who be recursive?


From: "Don Kendrick" <don () netspys com>
Date: Thu, 30 Mar 2000 07:34:43 -0500

Will you be running an external (either primary or secondary for the
domain)? I usually have the internal forward the request to the external
(usually running on the same box/firewall) then let the external handle
it....

Don
-----Original Message-----
From: Lance Spitzner <lance () spitzner net>
To: firewall-wizards () nfr net <firewall-wizards () nfr net>
Date: Thursday, March 30, 2000 2:39 AM
Subject: [fw-wiz] Split DNS, who be recursive?


Looking for architect opinions on Split DNS.
How do you configure your Internal DNS server?

When someone on your internal network queries
an Internet address, such as www.intel.com.

Do you ...

1.  Have your internal server do the query,
starting with the root servers?

2.  Have your internal server ask an upstream
DNS server to do the query (such as your ISP).

3. Have your internal server redirect the
client to another DNS server?

Looking for security pros/cons of each option.

Thanks!

Lance Spitzner
http://www.enteract.com/~lspitz/papers.html




Current thread: