Re: NetReg: Selective DNS Forwarding As a Method to Allow Self-Help From Quarantine Networks--BIND Configuration

New Message Reply Date view Thread view Subject view Author view Attachment view

From: Robert Lowe (Robert.H.Lowe@lawrence.edu)
Date: Wed Jul 14 2004 - 10:18:31 CDT


Ricardo Stella wrote:

> I've been playing yesterday with selective DNS forwarding...
>
> The problem with the suggestion presented, is that you'll really be
> running four DNS servers:
>
> a) NetReg with selective forwarding
> b) Dummy DNS (like the standard NetReg dummy one)
> c) Primary
> d) Secondary
>
> (You could say three, but not running a secondary ???)
>
> I need to simplify this down to 'TWO'. That is, Primary and Sec. The
> only way would be to use views.
>
> I did manage to get this down to three boxes. That is, a) and b) are
> both running on the same NetReg box, each listening on a different
> interface. But I should be able to run this directly on the existing
> DNS servers with views.
>
> Any ideas on how do accomplish this ?

First, a and b are the same thing. Master or slave zones of any type
(in this case they are forward zones) are referenced first. After that,
the root hints are consulted, and this is where the "default" answer
pointing to your NetReg box comes from. So a and b do not require
separate instances of named.

Second, unless you use multiple network interfaces, you do not want to
run one of your production DNS servers there, because you mark the
nameserver on that address as bogus.

You should have at *least* two nameservers, even if you have offsite
slaves. So why not run a+b on your NetReg box, and leave your other
two nameservers alone?

-Robert

**********************************************************************
To unsubscribe from this list, send an e-mail message to
majordomo@southwestern.edu containing a single line with the words:
unsubscribe netreg
Send requests for assistance to: owner-netreg@southwestern.edu
**********************************************************************


New Message Reply Date view Thread view Subject view Author view Attachment view

This archive was generated by hypermail 2.1.4 : Thu Aug 12 2004 - 12:01:46 CDT