Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: split DNS may not be necessary
From: *Hobbit* <hobbit @ avian . org>
Date: Sat, 1 Apr 1995 01:37:24 -0500
To: firewalls @ greatcircle . com

[Yes, I'm a week behind in my mail... it's too LOUD!]

If you want your firewall-forwarder machine to be the primary MX for your
"hidden" machines, but avoid having to do the split DNS thing, you can turn on
OwTrue in your sendmail [8.6.10] cf file and then wildcard or specifically MX
the inside hosts in your regular "exposed" DNS.

This should make Sendmail forward directly to the hidden hosts instead of
erroring out when the "best MX" would cause a loop.  Eric seems to think it's a
bad idea and says as much in the code [see src/domain.c], but hey, if it
works...

Caveat: I haven't actually *tested* this, and would appreciate a holler from
someone who has or intends to...

_H*

Indexed By Date Previous: Re: protecting username/password across the unsecure net
From: Jim Thompson <jim @ Tadpole . COM>
Next: Re: Outgoing ftp and filters
From: Brent @ GreatCircle . COM (Brent Chapman)
Indexed By Thread Previous: compiling portmap_3
From: Jochen Egger <egger @ N-E-T . de>
Next:
From: (nil)

Google
 
Search Internet Search www.greatcircle.com