Solved

using dns in dmz for queries.  Good Idea?

Posted on 2014-07-22
2
470 Views
Last Modified: 2014-07-29
Just wanted some general ideas about preventing AD servers from DNS lookups (just forwarding) and instead use a DNS server in the DMZ (probably Linux) doing the actual lookups.  Our security guy wants to do this and was wondering what the implications are.

Has anyone had any good or bad experiences with this kind of setup?  

I assume it's not that common any more?
0
Comment
Question by:billFmurray
2 Comments
 
LVL 57

Expert Comment

by:Cliff Galiher
ID: 40212825
Well, many things in AD *need* DNS to work right, so getting such a setup would still require the DMZ DNS server to talk to the AD DNS server, virtually eliminating any security benefit. I'm not sure I understand the purpose.
0
 
LVL 26

Accepted Solution

by:
DrDave242 earned 500 total points
ID: 40215650
Just wanted some general ideas about preventing AD servers from DNS lookups (just forwarding) and instead use a DNS server in the DMZ (probably Linux) doing the actual lookups.
Are you referring to external lookups (i.e., resolution of internet names)? DNS is used extensively for internal lookups by everything in the domain, so you wouldn't want to restrict that, but yes, you can restrict external lookups if you'd like. Your domain controllers can be configured to use the DMZ server as their only forwarder, and that server can then do the dirty work. You can then configure the firewall so that only DNS queries from your DCs are allowed to pass from the LAN to the DMZ, and only DNS queries from the DMZ server are allowed to pass through to the internet.

One disadvantage that I can see is that there's a single point of failure anytime you use only one forwarder: if your DMZ DNS server goes down, nobody in the domain will be able to get to the internet until it comes back up or you do a bit of reconfiguration.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question