Re: internal root and authoritative DNS

This is a discussion on Re: internal root and authoritative DNS within the Bind Users forums, part of the DNS and Related Forums category; Brad Knowles wrote: >At 7:22 PM -0500 2005-03-21, Barry Margolin wrote: > > > >>&...


Go Back   Usenet Forums > DNS and Related Forums > Bind Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-22-2005
Kevin Darcy
 
Posts: n/a
Default Re: internal root and authoritative DNS

Brad Knowles wrote:

>At 7:22 PM -0500 2005-03-21, Barry Margolin wrote:
>
>
>
>>> Now, if you try to mix an internal root with a nameserver that is
>>> supposed to communicate with the outside world, that is likely to run
>>> into some problems.
>>>
>>>

>> Shouldn't you be able to do it with views? You could have one view with
>> a master zone for ".", and another view with a hints zone for ".".
>>
>>

>
> That would be an interesting test. I would expect it to fail,
>because I don't think that the views mechanism applies to hints, and
>I think the internal versus external views would need to be operating
>from different hints.
>

First of all, why do you think hints would be excluded from "view"
differentiation? Secondly, one of the views in the configuration
described doesn't even need hints, because it's master for the root
zone. What Barry describes should work just fine. In fact, if an
organization had only 1 server and 1 IP address to use for internal and
external DNS, and for whatever reason insisted on having an
internal-root architecture, this is what they'd *have* to do. While
questionable from a security standpoint, I'm sure ISC/Nominum has
contemplated and probably tested such a minimalistic implementation of
"view"s.

- Kevin




Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:27 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0