Solved

DNS Redirects not working

Posted on 2008-06-26
1
720 Views
Last Modified: 2012-06-22
We use an external DNS service to handle DNS queries (www.dnsmadeeasy.com). We just installed a brand new Cisco ASA 5510 Firewall and the Juniper router in question. All DNS http re-directs that we try that point to an address on the external interface of the router will not load a web page if you are on the inside network. All DNS http re-directs that point to the actual private address on our network do work. However, if you are not on the inside network, the DNS redirects that point to an external ip address do work. We tried opening the firewall and seeing if it was a port issue, but it was still unable to communicate, not to mention, the ports work externally. We think it might be the router. Does anyone have any suggestions on getting our dns entries to work on our inside network?
0
Comment
Question by:IcueTV
1 Comment
 
LVL 70

Accepted Solution

by:
Chris Dent earned 125 total points
ID: 21879268

Hey,

It's a routing restriction I'm afraid. It's very difficult to connect to a device using NAT if the destination is on the same network as the client.

The solution is simple, if a bit of extra administration.

Do you have an internal DNS Server? You must create entries and zones on the DNS Server so that those public domains resolve to private IPs instead of public ones for clients within your network.

For instance, if you had an MS DNS Server you could do the following to regain access to an internally hosted public site:

1. Open the DNS Console
2. Right click on Forward Lookup Zones and add a new Zone.
3. Set the Zone to Primary (and AD Integrated if you have that)
4. Name the zone either yourpublicdomain.com or www.yourpublicdomain.com (I'll come back to that)
5. Disable Dynamic Updates
6. Add Host (A) Records to match the names to internal IP addresses

The two choices of name for the zone represent two different ways of approaching this.

If you use yourpublicdomain.com you must include every other address within the zone if you expect to resolve it. Otherwise your DNS server will rightfully say the address doesn't exist. In this case, and in this example you would add a www Host (A) Record with the internal IP.

If you use www.yourpublicdomain.com instead you allow the server to resolve names only for www, leaving everything else in yourpublicdomain.com to go out to the normal DNS Servers. In this case you would add a Host (A) Record with a blank name pointing at the Internal IP. That makes the "(same as parent folder)" record, and will resolve the zone name, in this case www.yourpublicdomain.com, back to the specified IP.

Hope that all makes sense!

Chris
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
active directory 3 25
domain controller migration seems succesful, however.... 9 60
DNS error assumed 8 42
Is it possible to host a website on a windows vps 4 27
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
Resolve DNS query failed errors for Exchange
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now