Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Dual-DNS Problems
From: Chris Tyler <chris @ dejong . com>
Date: Mon, 2 Oct 1995 14:49 EDT
To: Firewalls @ GreatCircle . COM

Back with more dual-DNS problems.

Background: DNS server 1 is internal DNS, can't reach the real 
world directly, but can reach server 2. Server 2 is external DNS 
and 'forwarder' for internal DNS server 1.

Situation 1: DNS server 1 'slave' flag in named.boot is *not 
present*. DNS resolves are done quickly and correctly the first 
time, but server 1 keeps generating UDP packets aimed at outside 
servers (which can't reach outside of the secure net).

Situation 2: DNS server 1 'slave' flag in named.boot *is* present. 
Non-cached DNS resolves requested by internal hosts often 
(usually?) fail on the 1st tty, and sometimes on the 2nd, but 
almost always resolve on the 3rd try. No UDP packets from server 1 
are aimed at real-world servers.

Sounds like a timeout problem, but this doesn't make sense, because 
the timeout should happen in Situation #1 as well. *Why* is this 
happening? Any help... TIA.

Chris Tyler	Chris @
 DeJong .
 Com	CTyler @
 Oxford .
 Net
Systems Development Manager, Wm. De Jong Enterprises Inc.
+1-519-424-9007 / fax +1-519-424-2399



Indexed By Date Previous: Re: [none]
From: Bernhard Schneck <Bernhard_Schneck @ GeNUA . DE>
Next: Re: How secure is a WAN then?
From: Richard Reno <rreno @ carsinfo . com>
Indexed By Thread Previous: Re: [none]
From: Goran Svensson <goran @ btj . se>
Next: Re: Dual-DNS Problems
From: Petter H{ggman <Petter . Haggman @ lule . frontec . se>

Google
 
Search Internet Search www.greatcircle.com