Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: DNS Proxy and Internal Root Name Ser
From: "Hicks, Rick" <RHicks @ hussmann . com>
Date: Thu, 2 Jan 1997 13:19:00 -0600
To: Jean-Francois ZWOBADA <zwobada @ apogee-com . fr>, "'Firewalls List'" <firewalls @ greatcircle . com>

>Sorry... That's probably due to my poor english but I must confess I   
mised
>something in your explanation... "The root only needs to
>>have references to hosts that are authoritative for the domain(s), they   
    

>>do not need to be, or should be, nameservers for a domain."
>What do you mean exactly ?

I guess I should explain the assumptions I made.  I assumed that you have   
internal nameservers for you're domain that are not listed as   
authoritative with InterNIC.  I also assumed that you have already set up   
an internal *root* nameserver situation that will spoof the internal   
servers into believing that they are authoritative for the domain even   
though they cannot, or you don't want them to, communicate with true   
Internet root nameservers.  What I have just explained is what I and many   
other people have setup.

The difference I saw was this:  You are using you're internal *root*   
nameserver to resolve queries.  The internal *root* should not have host   
data in it and should not be used to resolve names.  It should run with   
references to the internal nameservers and be listed in these internal   
nameserver's root.db (or root.cache) file.  No client should be using it   
for name resolving; they should use the other nameservers that you have   
setup as primary and secondaries.

If my assumptions are incorrect let me know.

Also, it may be that you have confused the terms 'root' and 'primary'   
when it comes to nameservers.  Please check to see that this is not the   
case.


Rick

________________________________________________
Rick Hicks
Systems Specialist
Hussmann Corporation
rhicks @
 hussmann .
 com
http://www.hussmann.com  

Indexed By Date Previous: RE: Air Force Web Site Hacked -Reply
From: Matthew Thompson <mthomps1 @ kiwitech . co . nz>
Next: NT NAT
From: "Jamie Thain" <jthain @ cat . bbsr . edu>
Indexed By Thread Previous: RE: DNS Proxy and Internal Root Name Ser
From: "Hicks, Rick" <RHicks @ hussmann . com>
Next: RE: DNS Proxy and Internal Root Name Ser
From: Jean-Francois ZWOBADA <zwobada @ apogee-com . fr>

Google
 
Search Internet Search www.greatcircle.com