[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



<a  rel="nofollow" href="http://www.etherboy.com/dns/chrootdns.html";>http://www.etherboy.com/dns/chrootdns.html</a>
<a  rel="nofollow" href="http://tldp.org/HOWTO/DNS-HOWTO-10.html";>http://tldp.org/HOWTO/DNS-HOWTO-10.html</a> - bottom of the
page, is where I found the link.

HTH




--- &quot;Cordell, Ron&quot; &lt;ron.cordell at sipstorm.com&gt; wrote:

&gt; Jerald,
&gt; 
&gt; Can you recommend a source for learning more about
&gt; configuring a split
&gt; DNS and other issues like that? 
&gt; 
&gt; Thanks for the response -
&gt; 
&gt; -ronc 
&gt; 
&gt; -----Original Message-----
&gt; From: ale-bounces at ale.org [<a  rel="nofollow" href="mailto:ale-bounces";>mailto:ale-bounces</a> at ale.org] On
&gt; Behalf Of
&gt; Jerald Sheets
&gt; Sent: Thursday, November 18, 2004 9:44 AM
&gt; To: 'Atlanta Linux Enthusiasts'
&gt; Subject: RE: [ale] DNS Questions
&gt; 
&gt; You may already be in luck.
&gt; 
&gt; FC2 came with BIND in a chroot jail already
&gt; preconfigured.   I haven't
&gt; looked, but I think FC3 has followed suit.
&gt; 
&gt; What you're probably looking for is what is called a
&gt; &quot;split DNS&quot;
&gt; configuration where your DMZ DNS server(s) are outward
&gt; resolving/looking, and your internal is inward only.
&gt; 
&gt; Having said that, keep in mind that you can still refer
&gt; to www.blah.com
&gt; from inside your private network, and if configured
&gt; correctly, your
&gt; router will route to the appropriate box, regardless of
&gt; private
&gt; interface.
&gt; 
&gt; I have a nat box doing translation to my internal systems
&gt; (all of which
&gt; have private IP's), but I refer to them all by their
&gt; public names.  The
&gt; NAT box sends my requests to the appropriate internal
&gt; machines.  I just
&gt; keep up with their public IP designations on the DNS
&gt; boxes (2) and
&gt; everything works without having to fiddle with the
&gt; private IP space.
&gt; 
&gt; --Jerald
&gt; 
&gt; 
&gt; &gt; -----Original Message-----
&gt; &gt; From: ale-bounces at ale.org [<a  rel="nofollow" href="mailto:ale-bounces";>mailto:ale-bounces</a> at ale.org]
&gt; On Behalf Of 
&gt; &gt; Cordell, Ron
&gt; &gt; Sent: Thursday, November 18, 2004 9:32 AM
&gt; &gt; To: ale at ale.org
&gt; &gt; Subject: [ale] DNS Questions
&gt; &gt; 
&gt; &gt; Hi everyone,
&gt; &gt; 
&gt; &gt; I'm new to the list, but not necessarily to the group
&gt; :)
&gt; &gt; 
&gt; &gt; I have a couple of DNS questions I was hoping people
&gt; could help me out
&gt; 
&gt; &gt; with.
&gt; &gt; 
&gt; &gt; The first question is network topology and where to
&gt; deploy DNS 
&gt; &gt; servers.
&gt; &gt; Let's say I have a segmented network, with a DMZ in
&gt; front of a 
&gt; &gt; firewall, and then two or three separate networks
&gt; behind the firewall.
&gt; 
&gt; &gt; I need to set up DNS so that all these servers can
&gt; resolve their 
&gt; &gt; private, &quot;internal&quot; names, but also so that the
&gt; machines in the DMZ 
&gt; &gt; can use the DNS. Seems like I need a DNS
&gt; primary/secondary pair in the
&gt; 
&gt; &gt; DMZ, and also another DNS in each network segment
&gt; behind the firewall.
&gt; 
&gt; &gt; Can anyone steer me to a good place to get a good
&gt; understanding of how
&gt; 
&gt; &gt; I should set this sort of thing up?
&gt; &gt; 
&gt; &gt; The second questions is about how to secure bind. We
&gt; are using Fedora 
&gt; &gt; Core 3. I've been reading that bind should be in a
&gt; chroot jail. This 
&gt; &gt; sounds like a pretty good practice. What other
&gt; suggestions do people 
&gt; &gt; have for securing bind?
&gt; &gt; 
&gt; &gt; Thanks in advance for pointing me in the right
&gt; direction.
&gt; &gt; 
&gt; &gt; Ron Cordell
&gt; &gt; 
&gt; &gt; 
&gt; &gt; _______________________________________________
&gt; &gt; Ale mailing list
&gt; &gt; Ale at ale.org
&gt; &gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
&gt; 
&gt; _______________________________________________
&gt; Ale mailing list
&gt; Ale at ale.org
&gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
&gt; 
&gt; 
&gt; _______________________________________________
&gt; Ale mailing list
&gt; Ale at ale.org
&gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>
&gt; 


=====
Kevin Stoll
<a  rel="nofollow" href="http://kevinstoll.com/";>http://kevinstoll.com/</a>

OpenSource Software...FREE!
Angering Bill Gates...priceless.
============================================================


		
__________________________________ 
Do you Yahoo!? 
The all-new My Yahoo! - Get yours free! 
<a  rel="nofollow" href="http://my.yahoo.com";>http://my.yahoo.com</a> 
 


</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<ul><li><strong>Follow-Ups</strong>:
<ul>
<li><strong><a name="00819" href="msg00819.html">[ale] DNS Questions</a></strong>
<ul><li><em>From:</em> kaboom at gatech.edu (Chris Ricker)</li></ul></li>
</ul></li></ul>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00797" href="msg00797.html">[ale] DNS Questions</a></strong>
<ul><li><em>From:</em> ron.cordell at sipstorm.com (Cordell, Ron)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00815.html">[ale] Hoping someone can offer some advice</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00817.html">[ale] kppp &amp;  smartlink soft modem</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00800.html">[ale] DNS Questions</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00819.html">[ale] DNS Questions</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00816"><strong>Date</strong></a></li>
<li><a href="threads.html#00816"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>