18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

10<br />

What is DNS?<br />

10-2 Domain Name System (DNS)<br />

The <strong>Sidewinder</strong> <strong>G2</strong> <strong>of</strong>fers two main DNS configurations: Transparent<br />

DNS and <strong>Sidewinder</strong>-hosted DNS. The sections below explain each<br />

configuration method.<br />

Note: An excellent source <strong>of</strong> information on DNS is the Internet S<strong>of</strong>tware Consortium<br />

Web site at www.isc.org. Some background information is also provided in the<br />

<strong>Sidewinder</strong> <strong>G2</strong> installation documentation. The book DNS and BIND, by Albitz & Liu<br />

(O’Reilly & Associates, Inc.) is also a popular reference.<br />

About transparent DNS<br />

Transparent DNS represents a simplified DNS configuration. When<br />

transparent DNS is configured for the <strong>Sidewinder</strong> <strong>G2</strong>, DNS traffic<br />

passes transparently through the <strong>Sidewinder</strong> <strong>G2</strong> using a proxy. The<br />

<strong>Sidewinder</strong> <strong>G2</strong> uses proxy rules that pass all DNS traffic by proxy to<br />

its appropriate burb. DNS requests are then handled by the remote<br />

servers. Other machines do not “see” the <strong>Sidewinder</strong> <strong>G2</strong>, which<br />

means there is minimal disruption to your current DNS configurations<br />

throughout your network.<br />

Configuring transparent DNS requires specifying the IP address <strong>of</strong> one<br />

or more remote DNS servers. (Alternative server addresses may be<br />

used for redundancy.) If a customer is using NAT through the<br />

<strong>Sidewinder</strong> <strong>G2</strong>, they should also have an additional DNS server on the<br />

outside <strong>of</strong> their network. The external DNS server handles the<br />

external zones <strong>of</strong> your network and its addresses. This configuration<br />

allows you to control which addresses are visible to the outside<br />

world.<br />

Note: Transparent DNS is designed for simple DNS configurations. Complex DNS<br />

configurations may require DNS services to be hosted directly on the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

About <strong>Sidewinder</strong> hosted DNS<br />

<strong>Sidewinder</strong> hosted DNS represents a more complex DNS<br />

configuration that utilizes the integrated <strong>Sidewinder</strong> <strong>G2</strong> DNS server.<br />

When configured for hosted services, DNS servers run directly on the<br />

<strong>Sidewinder</strong> <strong>G2</strong>. This places the DNS server(s) on a hardened<br />

operating system, preventing attacks against these servers from<br />

penetrating your network.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!