Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux Hosts
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Servers
Reload this Page Linux DNS in DMZ Zone
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Servers Anything server related, Apache, MySQL, Samba, server security, sendmail, exim, etc

Reply
 
Thread Tools Display Modes
Old 04-25-2008   #1 (permalink)
gaurav9gupta
Just Joined!
 
Join Date: Aug 2007
Posts: 2
Smile Linux DNS in DMZ Zone

Hi Linux Gurus,

I need help for Linux DNS on which I can enable security for my organisation.
Hope I will be able to do below mentioned (# 3 & # 4) through Linux DNS.
LINUX DNS server is in Cisco Firewall DMZ zone.

I have four queries:

1. Linux DNS should able to resolve the DNS query for internet. ( I can do this).

2. Linux DNS should send resolution of my domain xyz.com, zone hosted on server. (I can do this).


NEED HELP FOR BELOW MENTION Queries

3. Any other query for any domain other then xyz.com domain should not be resolved.

4. Should reply queries from authoritative server for xyz.com doamin should be resolve.

PLEASE HELP!!!

Thanks in Advance
Gaurav
gaurav9gupta is offline   Reply With Quote
Old 04-25-2008   #2 (permalink)
wildpossum
Just Joined!
 
wildpossum's Avatar
 
Join Date: Apr 2008
Location: Sydney/Australia
Posts: 74
Send a message via Skype™ to wildpossum
Firstly I am not a DNS experienced person but generally;

A> You need to ensure that the /etc/resolv.conf file in each end-point machine has the correct domainname, domainsearchnames within. Usually your DHCP service would set these up, as I am sure our organisation has done so already.

B> If I understand your point 3. you don't want any other domain to be resolved? The main point of DNS is to resolve domains somewhere along the path, so unless you want to hide a owned domain within your organisation (I couldn't see why) why would you want to you would do it this way? Simply don't add it to your DNS service.

C> Your point 4., should be not a problem but you need to read up on HOW-TO. I strongly suggest you do a google search on Linux DNS HOWTO and go from there.

Cheers.
__________________
Grahame
AMD Phenom(QuadCore), 8GB, 3ware RAID6 1.8TB, HD3850(512MB) ..etc.
wildpossum is offline   Reply With Quote
Old 04-25-2008   #3 (permalink)
gaurav9gupta
Just Joined!
 
Join Date: Aug 2007
Posts: 2
Hi Grahame,

Thanks for you inputs.

Regarding Point # 3 & 4 I will clarify more that:

I don't want to hide my domain inside my organisation. I need to block domain other then my xyz.com domain from internet. In simple words any internet user should not use my DNS IP address for resolving domain other then xyz.com domain.

Hope it will clarify why I need point #3 on Linux DNS.

If you please suggest design of linux DNS then it would be great becuase I have placed DNS in Cisco PIX DMZ and static Nat DMZ IP with public IP address.

Thanks,
Gaurav
gaurav9gupta is offline   Reply With Quote
Old 05-14-2008   #4 (permalink)
tituskalvarija
Just Joined!
 
Join Date: May 2008
Posts: 1
you can use VIEW in named.conf

Quote:
view "<view-name>" — Creates special views depending upon the host contacting to the nameserver. This allows some hosts to receive one answer regarding a particular zone while other hosts receive totally different information. Alternatively, certain zones may only be made available to particular trusted hosts while non-trusted hosts can only make queries for other zones.
tituskalvarija is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT. The time now is 01:08 AM.

Powered by vBulletin 3.6.8 ©2000 - 2007, content relevant URLs by vBSEO, Property of Core Root.

Content Relevant URLs by vBSEO 3.0.0