Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: NAT and DNS ?
From: Dennis Morton <Dennis_Morton @ INS . COM>
Date: Wed, 26 Feb 1997 09:31:11 -0600
To: Joerg Kummer 41 61 68 88132 <JOERG . KUMMER @ Roche . COM>
Cc: firewalls <firewalls @ GreatCircle . COM>

Joerg,
If your NAT implemenation will allow it, establish a static private<->public mapping for the Web server (i.e. tell the NAT to always translate 10.1.1.1 to 192.130.1.1 and vice versa). In your internal DNS, map the Web servers name to the statically-mapped internal address. 


At 03:06 PM 2/26/97 +0100, Joerg Kummer 41 61 68 88132 wrote:
>Let me re-phrase the question:
>
>We plan to attach a network to the Internet via a RFC1631 NAT/fw.
>There is a resource (e.g. WWW server) which is used by internal and Internet
>users. The resource is attached to the internal network. The DNS name of the
>resource should be the same for internal and Internet users.
>
>Q: How could DNS be set up ? 
>   Is it a good approach to establish separate DNS 'namespaces'/servers -
>   one for internal and one for Internet users - which resolve the same name
>   to different IP addresses.
>
>   If so, is the method described in the FAQ a good way ?
>   (The FAQ describes DNS hiding of internal hosts which seems to be a very
>   similar problem)
>
>Unfortunately RFC1631 does not cover DNS issues...
>
>regards
>          joerg

-----------------------------------------------------------------------
Dennis Morton				<mailto:dennis_morton @
 ins .
 com>
International Network Services (INS)	(voice) 214-392-3545 x170
14160 Dallas Parkway, Ste. 200		(alpha pager) 1-800-467-1467
Dallas, TX  75240
-----------------------------------------------------------------------

Indexed By Date Previous: Re: Firewall Sparc platforms?y
From: Brian Tackett <cym @ acrux . net>
Next: Re: NAT and DNS ?
From: Irwin Lazar <lazar @ netevolve . com>
Indexed By Thread Previous: Re: NAT and DNS ?
From: Joerg Kummer 41 61 68 88132 <JOERG . KUMMER @ Roche . COM>
Next: [no subject]
From: Ng Bingsheng <benedw @ pacific . net . sg>

Google
 
Search Internet Search www.greatcircle.com