Thanks for the respons
Here is my present setu
public DNS ----- Firewall ----- local domain (AD) & User System
xy.com xyhyd.co
The public DNS has our MX records & web site resolution addressess
we have a local Domain (AD) and local DNS for LAN users
The primary DNS is pointed to itself and secondary is pointed to Public DNS in TCP/IP properties
In the enable forwarders i have public DNS server entry in it.
This is my local AD and DNS setup
In the public DNS server, i have public IP assigned to this server and the primary DNS is pointing to itself in TCP/I
In the enable forwarders i have ISP DNS server entries in it
Because of security constraints i want to move public DNS inside firewall
If i move public DNS inside firewal
1. What are the ports to be opened in firewall for DN
2. what are the changes to be made in the public DNS server ( TCP/IP settings, Forwarders etc) if i am going to assign a local LAN ip for public DNS serve
3. what are the changes to be made to local DNS server
Hope this is clear
Thanks in advanc
Satheesh Kiran
----- Kevin D. Goodknecht [MVP] wrote: ----
In
Satheesh Kiran said:
Thanks for the Repl
in DNS server properties should i point to the local LAN ip or shou
i still point to the same public IP which i was using earlier
public IP in the preferred DNS servers in TCP/IP properties windo
You didn't say any local machines were using this DNS server. This ca
change things if you have any local sites and local machines using this DN
server. Any site hosted by this DNS that has both local and public access i
going to be a problem
Any site that is hosted locally behind the NAT device won't work with th
public address. You definitely don't want to put private records in a Publi
Zone
You can have a public DNS behind NAT as long as it does not resolve site
and servers behind the same NAT device. For that you need two separate DN
servers, one for the internal users and one for the external users
--
Best regards
Kevin D4 Dad Goodknecht Sr. [MVP
Hope This Help
===========================
--
When responding to posts, please "Reply to Group" via you
newsreader so that others may learn and benefit from your issue
To respond directly to me remove the nospam. from my email
=========================================
http://www.lonestaramerica.com
=========================================
Use Outlook Express?... Get OE_Quotefix
It will strip signature out and mor
http://home.in.tum.de/~jain/software/oe-quotefix
=========================================
Keep a back up of your OE settings and folders wit
OEBackup
http://www.oehelp.com/OEBackup/Default.asp
=========================================