Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Internal's root.cache
From: c . palmer @ dtt . co . nz (Chris Palmer)
Date: Fri, 21 Apr 1995 14:37:45
To: Firewalls @ GreatCircle . COM

<blast @
 worldbit .
 com> (Tim Keanini) wrote:
>I am going to de-lurk and ask:
>
>InternalDNS has 'forwarders' that point to ExternalDNS
>and my ExternalDNS box has the /etc/resolv.conf that points to InternalDNS 
>box.
>
>OK so far...
>
>My question is what do I put in my InternalDNS's root.cache?
>If I leave it the way it is with the current root.cache from
>RS.INTERNIC.NET the InternalDNS server is trying to send .domain messages
>to those IP's and gets blocked by my CHOKE router.

There is a option in named.boot called "slave". Use this in the internal DNS, 
and it only talk to the forwarders (i.e. it ignores the root.cache). The only 
forwarder we list is the firewall. Beware, though, of versions of BIND prior 
to 4.9.x. These have a timing bug which produces sporadic "server failed" 
responses from the slave.

---------------------------------------------------------
Chris Palmer
Deloitte Touche Tohmatsu, Auckland, New Zealand
c .
 palmer @
 dtt .
 co .
 nz

Indexed By Date Previous: transparent proxy from outside
From: brian @ ilinx . ilinx . com (Brian J. Murrell)
Next: Re: C & B 'Choke' Router config
From: cwerner @ hsdemo . merit . edu (Christopher L. Werner)
Indexed By Thread Previous: Re: Internal's root.cache
From: thierry agassis <thierry @ osftag . geo . dec . com>
Next: Re: Self activating E-mail viruses?
From: Brent @ GreatCircle . COM (Brent Chapman)

Google
 
Search Internet Search www.greatcircle.com