Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Strange DNS forwarding

Status
Not open for further replies.

efector

IS-IT--Management
Dec 10, 2003
234
US
Hello. I have my internal DNS servers set up to forward requests to my DNS server in our DMZ, which in turn make/forward requests out to the internet. The odd thing that is happening, is that my internal DNS servers are making requests out to the internet(or trying to)themselves. I have set my internal DNS server to forward ONLY to my DMZ DNS servers. Any help?

The internal servers are attempting DNS requests to the following(and this is only a partial list):

64.58.81.251,64.191.219.251,192.42.93.30,192.5.6.30,192.33.14.30,
216.27.75.45
 
So, if I want to have my internal DNS servers ONLY use the DMZ DNS servers, then I should DISABLE recursion, correct? Should I increase the timeout length? What is the downside of not allowing recursion?
 
This feature can be used for security purposes as it prevents your DNS servers contacting potential rogue DNS servers and can protect against cache poisoning.

If you want the DNS server to only use forwarders and not attempt any further recursion if the forwarders fail, select the Do not use recursion for this domain check box.

 
You can turn off recursion as the DMZ DNS servers will still perform the function.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top