9.1.3. Procedure – Setting up split-DNS configuration
Setting up a split DNS service is useful in networks where both external and internal name resolution is performed using the same DNS server – in this case the PNS firewall. Since hiding the internal namespace from external visitors is a basic security requirement, you have to set up the DNS service in a way that it does not resolve internal names for external resolvers. In other words, for all DNS zones stored on the server you have to specify which networks can query for records in the given zone.
Add the Text Editor component.
Select the template.
Two skeleton files are created, a
named.confand anamed.conf.shared.The
named.conf.sharedfile holds records and configuration settings that are shared between external and internal name resolution operations, whilenamed.confhas options to specify internal and external networks (internalipsandexternalips). These networks can then be referenced indb.domainnamefile(s) to specify which networks can have access to what records.For more information on split-dns configuration and DNS configuration in general, see Appendix B, Further readings.
Copyright: © 2021 Balasys IT Security
Send your comments to support@balasys.hu


