N
Niall Porter
Hi,
I'm at the end of my proverbial on this one. Can someone help?
SCENARIO:
We have a number of Win2k servers in a dual homed configuration
whereby one NIC connects to our LAN and the other to our DMZ for
serving FTP, web etc. We have two internal DNS machines and are
provided with addresses for two external DNS servers from our
connectivity provider.
I have set up the internal NIC's to use the internal DNS servers and
the external NIC's to use the external DNS. This seems to work fine
for a while (a day, few days anything up to a couple of weeks) then
suddenly the machines cannot be reached from outwith our LAN.
However, and this is the bit that strikes me as wierd, if I give the
external (DMZ connected) NIC's the INTERNAL DNS addresses, they work
fine. Very odd, because our firewall won't let DNS thru from the DMZ
to the LAN so these NIC's should not be able to contact our internal
servers for name resolution at all.
Aside from that we've done nothing special with the network config (no
static routes, no RRAS service etc). Common sense tells me that
internal NIC's should use internal DNS and external NIC's use external
DNS, or does common sense not apply to Windows 2000 server (silly
question..)?
I'm at the end of my proverbial on this one. Can someone help?
SCENARIO:
We have a number of Win2k servers in a dual homed configuration
whereby one NIC connects to our LAN and the other to our DMZ for
serving FTP, web etc. We have two internal DNS machines and are
provided with addresses for two external DNS servers from our
connectivity provider.
I have set up the internal NIC's to use the internal DNS servers and
the external NIC's to use the external DNS. This seems to work fine
for a while (a day, few days anything up to a couple of weeks) then
suddenly the machines cannot be reached from outwith our LAN.
However, and this is the bit that strikes me as wierd, if I give the
external (DMZ connected) NIC's the INTERNAL DNS addresses, they work
fine. Very odd, because our firewall won't let DNS thru from the DMZ
to the LAN so these NIC's should not be able to contact our internal
servers for name resolution at all.
Aside from that we've done nothing special with the network config (no
static routes, no RRAS service etc). Common sense tells me that
internal NIC's should use internal DNS and external NIC's use external
DNS, or does common sense not apply to Windows 2000 server (silly
question..)?