Hi, I have little experience with DNS and wondering if it would be possible to setup a DNS server that resolves public and private IP's which are only available to users on the internal network?
How would this be setup and work? Thanks in advance.
On your firewall allow your DNS server to reach/search only trusted DNS server ( like DNS servers provided by large ISPs), by adding the trusted DNS servers address as a "forwarder" in the servers DNS setup. With forwarder(s) in place, your internal DNS server is only allowed access/searching ability to the forwarder for DNS lookups, it is not allowed to search other public DNS servers. The server designated as the forwarder does the DNS lookkups and gives the DNS results to your server.
Block DNS access to the outside ( by denying at the firewall) for your workstations, only allow them access to your internal DNS server. Workstation should only have the internal DNS server as "preferred server" on the WKS network setup .
Your server should be protected by AV software, should not be used for Internet cruising and be checked with anti malware programs regularly.
This protects both the server and workstation from go to rouge DNS servers hell bent on distributing malware. Particularity this stops the workstations from being redirected to bad DNS servers by clicking on links found at hundreds of sites on the Internet and within Email .
........................................
"Computers in the future may weigh no more than 1.5 tons."
Popular Mechanics, 1949
Leak data? First of all there is no DNS data worth anything, secondly if setup as noted, the outside world has no access to your DNS server or workstations information, firewall blocks it.
........................................
"Computers in the future may weigh no more than 1.5 tons."
Popular Mechanics, 1949
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.