Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: split-brain DNS
From: "Marcus J. Ranum" <mjr @ clark . net>
Organization: V-One Corporation, Baltimore, MD Office
Date: Thu, 20 Jun 1996 16:17:21 -0400 (EDT)
To: Firewalls @ GreatCircle . COM
In-reply-to: <199606190800 . BAA08103 @ miles . greatcircle . com> from "Firewalls-Digest" at Jun 19, 96 01:00:22 am
Phone: 410-889-8569
Reply-to: mjr @ v-one . com

Steve Bellovin <smb @
 research .
 att .
 com> writes:
>	 The split-brain DNS is a problem when you have a domain and
>	 subdomains behind the firewall. The solution we know is to declare
>	 the DNS server of the parent domain as a secondary server for every
>	 existing subdomain. This solution is not really great since we can't
>	 resolve Internet names from a subdomain.
>	 We are currently using the 4.9.3-REV and testing the 4.9.4 of BIND
>	 but no improvement seems to be done...
>
>There will be a paper by Bill Cheswick and myself addressing some of
>these issues, to be presented at the Usenix UNIX Security Conference 7/22-25.

	I just recently got sick of the problem, and did a short
term hack that works pretty nicely. Basically, you extend the
syntax of resolv.conf to include specifiers saying "this domain
resolves against this server" and run all the applications on
the firewall linked against the modified resolver library. The
firewall runs a nameserver with a partial database that is public
and you insert patterns telling the firewall's applications to
resolve yourdomain.domain against your internal nameserver. It
just works.
	I've put a brief write-up how it works, and a patch
file (against some version or other of bind) on
http://www.clark.net/pub/mjr  under the section entitled "stuff."
It's completely unsupported, etc, etc. Do not take internally,
consult a doctor if accidentally ingested, etc, etc.

mjr.


Follow-Ups:
Indexed By Date Previous: Re: Pilot Network Services
From: manderse @ mordor@syseng.fbc.com (Mike Andersen)
Next: Re: freinds
From: Ali Khalaf <alik @ batelco . com . bh>
Indexed By Thread Previous: split-brain DNS
From: Steve Bellovin <smb @ research . att . com>
Next: Re: split-brain DNS
From: The Root of All Evil <toshio @ kamikaze . dnp . co . jp>

Google
 
Search Internet Search www.greatcircle.com