Solved

Windows 2003 Split DNS solution ?

Posted on 2014-07-23
3
50 Views
Last Modified: 2016-06-09
Hello everyone,

I have a question regarding DNS running on Windows 2003 server.  If I disable recursion  (from check box "Disable recursion (also disable forwarders" )) I cannot use my DNS server to resolve external IP.  For example everyting works internally but if I want to go to yahoo.com the page cannot be displayed.

Now you probably ask yourself why I want to disable recursion.  That's because we need to prevent DDoS
Anyways, I ticked off  the check box and bingo!  I am now protected.  One little thing.. there is no INTERNET !  Which likes in any organization, this is a NO GO.  

I think the solution is to implement split DNS, however I am not sure about it.  For example if I had "Disable recursion (also disable forwarders)" enabled the forwarders will not work.  Then I think that it does not matter what I add under Forwarders tab will not work (remember, forwarders are disabled)

Would appreciate if someone can point me in the right direction

Cheers
0
Comment
Question by:Bibecu
3 Comments
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 500 total points
ID: 40215358
This has nothing to do with split DNS from your description. You can disable recursion and forwarders and still have Internet name resolution as long as the root hints are enabled.  So, check the root hints tab and make sure they are all enabled.  

OTOH, you aren't vulnerable to a DNS-related DDoS attack unless you are allowing INCOMING traffic on your router on TCP port 53 (DNS).  The only reason to allow  this traffic would be if your internal DNS server is responding to requests from outside your internal LAN (other than through an IPSEC tunnel or other type of encrypted communication).
0
 

Author Comment

by:Bibecu
ID: 40229599
Very good idea, thank you!  Problem solved !
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn about cloud computing and its benefits for small business owners.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question