Great Circle Associates Firewalls
(December 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Question on a DNS setup for dual-homed gateway
From: list . firewalls @ optimum . net (optimum.net newsgate)
Organization: Optimum Group
Date: Wed, 17 Dec 1997 15:49:07 -0500
To: firewalls @ greatcircle . com

I have a question on setting up DNS for a dual-homed gateway firewall. A 
simplified diagram of part of our network would look something like this:

[modems] <---> [comm server] <---> [router] <---> [gateway] <---> [LAN]

There are a few services which are running on the gateway which both users 
on the LAN and on dialup need to get to.  There is no access from the modems 
directly to the LAN, since not all of the dialup users should have access 
to any of the machines on the LAN.

What we have now: There is a separate DNS for users on the LAN, which translates
the names of the services on the gateway to the ip address of the internal
interface. (e.g., mail.foo.com -> 1.2.3.4). There is also another DNS for users 
on dialup, which translate the names of the services on the gateway to the ip 
address of the external interface. (e.g., mail.foo.com -> 5.6.7.8).  Laptop 
users can point at one DNS while on the LAN, and the other while coming in from 
dialup, and can therefore keep their application settings the same (mail is 
always read from mail.foo.com).

What we would like: Some method, preferably without adding any new
hardware, to use one DNS server for both LAN and dialup. I've tried a test
(using BIND 8) where the name had two A records. This worked for the most
part, but suddenly the wrong ip address was consistently returned while
on dialup.

It sounds like address sorting might help here, but I've been told that address
sorting is no longer a part of BIND in version 8. And, I'm not sure how it would
handle dialup users, who do not directly share a network with the gateway

Is there any way to use one DNS on the central gateway machine (along with 
secondary name servers both inside and outside the firewall) ?

Thanks,

Steve Pfister
Optimum Group
srp336 @
 optimum .
 com

Indexed By Date Previous: +!%*!* mail!
From: "Takacs Istvan" <anonymus @ mail . matav . hu>
Next: Re: DoD Red Book...
From: "Gary Kessler" <g . kessler @ hill . com>
Indexed By Thread Previous: Re: +!%*!* mail!
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: unsubscribe
From: Onstott Ron <Onstott_Ron @ prc . com>

Google
 
Search Internet Search www.greatcircle.com