SUMMARY: DNS Access control

From: Wales Wong (wawong@asl.com.hk)
Date: Fri Jan 10 1997 - 03:17:07 CST


Hi SunManagers,

First of all, I'd like to thank all those who respond, includinng:

davem@solve.net
jacques.rall@za.eds.com
gautam@bwc.org
Gokhan.Ozkan@raksnet.com.tr
petrilli@uol.com
grevemes@VTC.TACOM.Army.Mil
Matthew.Stier@MCI.Com
bobw@kramer.filmworks.com
benji@hnt.com

I apologize if I miss anyone.

My original question:

Is it possible to setup a single DNS server such that internal users
can access the whole database, whereas the external users
can only access part of it (in the DMZ)?

The story is that my customer doesn't want the external world to
know what machines he has, while at the same time he allows the
external world to access his web server and ftp server.

I know one of the solutions is to put the external information on
his ISP, while setting up the DNS server for internal use only.
However, he wants to have exclusive control over the DNS server.
Is it possible?

Suggestion/Solution:

i) Using nis for internal lookup
ii) two DNS servers -- which is not actually what we want
iii) use the xfernets option of newer BINDS
        I haven't got the time to try it. I will give it a try when I have time.



This archive was generated by hypermail 2.1.2 : Fri Sep 28 2001 - 23:11:42 CDT