Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: DNS Configuration
From: "Ward D. Britton" <wardb @ xplus . com . au>
Date: Sat, 14 Jan 1995 12:03:14 +0000
To: firewalls @ greatcircle . com

Rich .
 Friedeman @
 corp .
 anixter .
 com responded...

     "Ward D. Britton" <wardb @
 xplus .
 com .
 au> writes
     >I have a requirement to setup a SINGLE system, which connects to the
     >local service provider via ppp as well as many other regional sites,
     >via direct PPP links.

     >As such, it is necessary to run DNS. But unfortunately, I cannot
     >figure out how to stop the addresses and hostnames for the other ppp
     >interfaces on this particular system, from bein propogated to the
     >world via DNS.

     One easy way to do it would simply be to give your DNS a wildcard
     entry for your domain.  Set up the beginning defining your domain as
     usual, and in the hosts section, just have an entry like

     generic    IN      A       123.234.*.*

     This will return either 'generic.mydomain.com' or UNKNOWN.mydomain.com
     (I don't remember which) for each host in your domain.  If you want
     particular hosts to be resolvable, and don't mind that the info is
     public put their entries before these.

Yes... it does resolve into unknown.mydomain.com.

     Unfortunately, this doesn't do you much good if you actually need to
     be able to resolve all of the hostnames interntally without the info
     getting out.

And this is the issue in  a nutshell.
Hosts need to be internally resolved, but not propagated to the world.

someone suggested to me that creating a 'split DNS' would do the trick, but my
understanding of this means that the DNS is split between systems, ie public
and internal, with the resolv.conf providing internal re-direction etc...  Is
this the case ?

     Rich
     rich .
 friedeman @
 anixter .
 com


---End of forwarded mail from Rich .
 Friedeman @
 corp .
 anixter .
 com

-- 
Ward D. Britton 			Email:	wardb @
 magna .
 com .
 AU
Senior Consultant			Fax: 	+61(2)452-2142
X + Open Systems Pty. Ltd.		Phone:	+61(15)702-002

Indexed By Date Previous: Sendmail & DNS? Secure enough for a firewall?
From: twalker @ acc . org
Next: FTP through firewall
From: Justin Harvey <jharvey @ netcom . com>
Indexed By Thread Previous: Re: DNS Configuration
From: Rich . Friedeman @ corp . anixter . com
Next: Firewalls and SUN systems
From: sdwix @ ttd . sandia . gov (Steven D. Wix)

Google
 
Search Internet Search www.greatcircle.com