Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 692
  • Last Modified:

Best practice for setting up DNS on Sonicwall

Hello Experts!

We have a few scenarios where I need to understand what the best practices should be for DNS at the firewall level.

Scenario 1: Windows server environments where SonicWALL doesn't handle DHCP or DNS, but rather Windows Server does. What should the DNS settings point to: a) the Windows DNS servers or b) Public DNS servers (ISP, etc.).

Scenario 2: Windows server doesn't exist or at least is not handling DHCP/DNS in the environment and SonicWALL is handling both DHCP or DNS. I'd assume DNS should be point to Public DNS servers (ISP, etc.).

Thanks!
0
Peter Wilson
Asked:
Peter Wilson
  • 2
  • 2
1 Solution
 
Blue Street TechLast KnightsCommented:
Hi Peter Wilson,

As a general rule, If Windows Servers are present at least one should be handling DHCP and DNS.

As a best practice for firewalls, specifically SonicWALL, irrespective of having Windows Servers in the environment or not you should have the SonicWALL's DNS point to the Public DNS servers whether that be the DNS provided by your ISP, 4-8's or OpenDNS, etc.

The primary reason for this is because the backend of SonicWALL security services uses it's internal DNS server to perform functions like licensing synchronization (mysonicwall.com), cloud security services (CFS, AppControl, Geo-IP, Botnet, etc.), CFS lookups, validations, and a number of various security service functions. In short it also reduces hops for these types of functions.

Hope that helps. Let me know if you have any other questions!
0
 
Peter WilsonAuthor Commented:
so no matter what I should be setting up the DNS to point to public ones? What about for site to site vpn traffic where there are two windows servers running DHCP?
0
 
Blue Street TechLast KnightsCommented:
Yes, if Windows is handing out DHCP is should be handing out DNS as well.
0
 
Peter WilsonAuthor Commented:
Great. Thanks! Your detailed response and  thorough knowledge was warmly welcomed.
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now