Firewall Wizards mailing list archives

Split DNS, who be recursive?


From: Lance Spitzner <lance () spitzner net>
Date: Wed, 29 Mar 2000 12:10:24 -0600 (CST)

Looking for architect opinions on Split DNS.
How do you configure your Internal DNS server?

When someone on your internal network queries
an Internet address, such as www.intel.com.

Do you ...

1.  Have your internal server do the query,
starting with the root servers?

2.  Have your internal server ask an upstream
DNS server to do the query (such as your ISP).

3. Have your internal server redirect the
client to another DNS server?

Looking for security pros/cons of each option.

Thanks!

Lance Spitzner
http://www.enteract.com/~lspitz/papers.html



Current thread: