Re: DNS Forwarders Question
- From: "Graham J" <graham@xxxxxxxxxxxxxxxx>
- Date: Thu, 3 Jul 2008 09:04:09 +0100
"Tim Gowen" <tim@xxxxxxxxxxxxxxxxxx> wrote in message
news:1ijhqqw.rag2zfhw4zomN%tim@xxxxxxxxxxxxxxxxxxxxx
Graham J <graham@xxxxxxxxxxxxxxxx> wrote:
OK so the internal clients should stay the same, relying on the internal
DNS
servers. These DNS servers should look to the internet router for the
DNS
server provided by your ISP. It's possible that the PIX runs a DNS
service,
in which case you should point the local DNS servers to that, and
configure
the PIX to look at the external DNS - depends what the BT router offers.
Does the PIX provide NAT? Why is there a router "inside the perimeter"?
What purpose does it serve?
Presumably the DNS servers are also web proxies/caches so that internal
clients never talk directly to the outside world?
You can choose to supply the DNS servers with a list of forwarders and/or
root hints, so that their external lookups bypass the firewall and router
and go directly to external DNS servers. This will obviously be quicker,
but will only be apparent when the local DNS cache does not have the
lookup
requested.
The router for the WAN predates internet access, so our routers have
really built up as needed rather than being integrated.
The internal clients never talk directly to the internet; the PIX does
NAT (and passes SMTP commands to the mail server) so there is no
internet-facing hardware apart from the firewall.
I think we need to see a complete network diagram. What is the WAN if not a
connection to the internet? Or do you have connections via private links to
networks at other sites?
Having said that, if it works at present, changing the ISP and the ISP's
router ***probably*** won't affect anything ....
--
Graham J
.
- Follow-Ups:
- Re: DNS Forwarders Question
- From: Tim Gowen
- Re: DNS Forwarders Question
- References:
- OT: DNS Forwarders Question
- From: Tim Gowen
- Re: DNS Forwarders Question
- From: Graham J
- Re: DNS Forwarders Question
- From: Tim Gowen
- Re: DNS Forwarders Question
- From: Graham J
- Re: DNS Forwarders Question
- From: Tim Gowen
- OT: DNS Forwarders Question
- Prev by Date: OTish - Thunderbird and UTF coding
- Next by Date: Re: Graphics Cards
- Previous by thread: Re: DNS Forwarders Question
- Next by thread: Re: DNS Forwarders Question
- Index(es):
Relevant Pages
|
Loading