External and Internal DNS

BaDaBooM

Golden Member
May 3, 2000
1,077
1
0
I'm dealing with a particularly stubborn network admin that has both the internal DNS and external DNS in the DHCP Settings for the clients. His stance is that if the internal ones don't work then they can at least get to the internet if they have the external ones also.

I've found some things on technet that explain how clients can cache negative results and also how clients avoid unresponsive DNS servers. However I've been looking for more proof/reasons why you don't want to do this (he doesn't value Microsoft much). This seems such an obvious thing not do do but I'm having trouble finding specific information as to why you don't do it this way. I've found lots of whitepapers and documentation but not with the details specific to this situation. Any help is greatly appreciated.
 

EatSpam

Diamond Member
May 1, 2005
6,423
0
0
I just point DNS to my internal servers. My internal server contains both my internal and external zones. I then have BIND set up on the firewall boxen to slave the outside zones. This way, I can use a nice simple Windows interface for my DNS management and BIND just replicates it for outside use.

Do you only have one internal DNS server? Two would be preferable.
 

Moonark

Senior member
Oct 9, 1999
387
0
0
Maybe this would help... On my work network I have 2 internal DNS servers each one is configured to point to my ISPs DNS servers as forwarders. My DHCP clients are set up to only point to the internal. If one cannot find the information locally, then the request is forwarded to the external DNS servers. In 4 years I have never had an issue using it this way. If you host your own servers, like I do... I have entries on the external DNS servers for the resource's external IP, then internally I use my private IPs.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: BaDaBooM
I'm dealing with a particularly stubborn network admin that has both the internal DNS and external DNS in the DHCP Settings for the clients. His stance is that if the internal ones don't work then they can at least get to the internet if they have the external ones also.

I've found some things on technet that explain how clients can cache negative results and also how clients avoid unresponsive DNS servers. However I've been looking for more proof/reasons why you don't want to do this (he doesn't value Microsoft much). This seems such an obvious thing not do do but I'm having trouble finding specific information as to why you don't do it this way. I've found lots of whitepapers and documentation but not with the details specific to this situation. Any help is greatly appreciated.

Sorry. He is correct.

Read up on how a DNS resolver works.

Client asks for IP address of host to the first DNS server listed. If that server returns negative answer then no more queries - done.
If client does not receive answer from 1st listed server then it tries second DNS server with the same query.

Meaning - if your internal DNS server is not answering queries the client will try its next name servers. Of course your internal DNS server should be a caching name server but that's beyond scope.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |