Solved

non-www www CNAME redirection

Posted on 2010-08-30
6
1,011 Views
Last Modified: 2012-05-10
Hi Guys,

I'm not sure whether the below rule is possible in DNS. Can some one confirm this

example.com  CNAME  www.example.com
www.example.com     A    192.0.32.10

and I will be configuring www.example.com as an A record at Load Balancers.
0
Comment
Question by:nlrreddy
6 Comments
 
LVL 57

Accepted Solution

by:
giltjr earned 167 total points
ID: 33563747
Depending on how you add/change DNS entries the www entry would typically come first and then the CNAME entry.

Assuming BIND9 you would have something like:

www              A 192.0.32.10
example.com. CNAME www.example.com
0
 
LVL 76

Assisted Solution

by:arnold
arnold earned 167 total points
ID: 33564569
No, that is not possible.
It is invalid to point the domain name as a CNAME to anything.
gilttjr, the order of record entry is irrelavent since the DNS server loads the data an organizes it as it sees fit without regard to which it saw first.  It is often suggested for ease of troubleshooting/reviewing DNS records/issues, to list them in level order.
domain
subdomains
.
.
hostname
.
.
.

The issue is with the CNAME record. Your zone will likely not load or if it does, it will create a loop where any request to example.com will be redirected because of the CNAME to look for a zone in www.example.com which will not exist.


You should do the reverse: define the domain with an A record pointing to an IP while the www record will be a CNAME to the domain.

example.com. A 192.0.32.10
www CNAME @
or
www CNAME example.com.
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 167 total points
ID: 33565499
arnold, order may not matter for most most DNS server software works.  However I have had some DSN server software spit out error message and not accept CNAME definitions because the occurred before the A record they were pointing to.   I have also used CNAME for domain names.  Both situations could have been bugs in the software I was using at the time.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 70

Assisted Solution

by:Chris Dent
Chris Dent earned 83 total points
ID: 33565558

It shouldn't permit you to, using a CNAME record where the resource is used by another record should make it cry (does not comply with the RFCs on use of CNAME records).

But there we go, I certainly won't argue that all software prohibits it, I only suggest it's bad practice :)

Chris
0
 
LVL 76

Assisted Solution

by:arnold
arnold earned 167 total points
ID: 33568183
giltjr,

I understand your point and it often deals with GUI based interface where they have to validate what you are entering against the existing data.  At times, the right side of the data entry was not being validate and at rare times led to the zone failing to load because the user entered the wrong thing for the record type.

I think bind9 if you make such entries and run the named-checkzone example.com where you cname the zone name, you will get an error message.

This is likely with registrars that provide DNS services.
I.e. as far as DNS is concerned, there is nothing inherently wrong with defining a CNAME to a record that does not exist i.e.
www CNAME nosuchthing

Looking up the record for www.example.com will return CNAME record that points to nosuchthing.example.com. The client will then lookup nosuchthing.example.com and will get the no such record and will end it at that.

The web based GUIs will validate local data
i.e. www CNAME nosuchthing will check whether there is a record nosuchthing.
but if you use
www CNAME nosuchthing.someotherdomain.com.
The record will likely be added.
0
 
LVL 61

Assisted Solution

by:gheist
gheist earned 83 total points
ID: 33574797
CNAME redirects all subtree to differnt name, so it causes infinite loop in resolver.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now