Solved

DNS Information

Posted on 2006-06-28
3
347 Views
Last Modified: 2013-11-30
Currently I have a customer with a website hosted on a webserver on there internal lan. The website can be accessed from the internet but not internally. This is because they have a firewall address in there DSN listed as the www record for the domain name the website uses. One thing that is confusing is that this company's IT guy would put in thier DNS every domain they had purchased. So the windows 2003 domain they use internally is in there with about 3 or 4 others. One of the others is where the website is being published from. I'll refer to it as site.com. In DNS for the zone site.com the www entry pionts to the firewalls outside address. The firewall reserves the internal connection of this address for its web managment console. I changed the www record for the site.com zone and they could access it internally and I could access it from my office. about 20 min. later the site was gone from the internet but still up internally. I changed the record back and it went away from the internal and was back on the internet. I thought the internal dns was only for internal use I didnt realize it propogated records up to the isp's dns. I thought about changing the websites ip address to something other than the firewalls external address but I think the firewall only supports one outside ip. The firewall is a watchguard soho 6.

Any suggestions in how to make the website available internally.

Can and should the dns propogation to the isp's be disabled and if so, how?

Also anyone have any suggested reading to learn more about advanced DNS?
0
Comment
Question by:officecare
  • 2
3 Comments
 
LVL 9

Accepted Solution

by:
NYtechGuy earned 250 total points
ID: 17002776

You have to add a DNS zone on your internal (read: not listed on your domain's internet record and not used by the internet to look up your domain) dns servers to direct your interenal clients to the INSIDE IP ADDRESSES.

You need to have it configured as such:

OUTSIDE DNS:  Points to OUTSIDE IP addresses

INSIDE DNS ZONE:  Points to internal IP addresses (192.168.1.x) where applicable, or has outside addresses where needed.  (example:  www.domain.com = 65.x.x.x & mail.domain.com = 192.168.x.x)
0
 

Author Comment

by:officecare
ID: 17003550
I think we are on the right track. They currently have a site.com zone on the internal DNS that pionts to the external address but when I changed the www record ip it changed it for everyone internal and external. How do I control what propogates to the isp dns servers vs what doesnt?

0
 
LVL 9

Expert Comment

by:NYtechGuy
ID: 17003654

They should be different servers- totally different hardware.

For instance, the external DNS that controls everything across the internet is *usually* hosted at the registrar (Network Solutions, Register.com, Bulkregister.com, etc) or at the web host (Interland, etc).

The internal DNS (which is where DNS for Active Directory is) would be on your Active Directory DOmain Controller (DC) which should be down the hall from you.

These two roles should NEVER be on the same server.  I can't tell you what a security risk that is if that's the case.

It is also recommended (to avoid issues like this) to have your AD Domain end with .local (yourdomain.local) as opposed to using the .com (your company.com).

To check what is what:

1. Go to this site:  http://www.networksolutions.com/whois/index.jsp
2. Enter your domain (yourdomainname.com) hit enter
3. On the domain record, at the bottom, see what servers are listed and write them down (hostname and IP address)

Are those IP addresses on your network?  

If you aren't sure what your external IP is, click this link:  http://whatismyip.com
- Is the IP address listed the same network as the ones from step #3?

Thanks,

Justin
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question