18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

What is DNS?<br />

In a hosted DNS configuration, the <strong>Sidewinder</strong> <strong>G2</strong> requires<br />

information about your DNS authority. Generally, there should be<br />

only one "master" name server for any fully-qualified domain, (such as<br />

nyc.bigbiz.com) also called a “zone”. There may be many "slave"<br />

servers, for redundancy and better performance, but they derive their<br />

information from the one master for each domain.<br />

You can configure <strong>Sidewinder</strong> hosted DNS to use a single server or<br />

split servers as follows:<br />

Hosted single server DNS—In a <strong>Sidewinder</strong> hosted single server<br />

configuration, one DNS server is hosted on the <strong>Sidewinder</strong> <strong>G2</strong> and<br />

handles all DNS queries. The server is protected by the <strong>Sidewinder</strong><br />

<strong>G2</strong> hardened OS, preventing attacks from penetrating your<br />

network. A single server configuration is generally used when you<br />

have no concerns for keeping your internal network architecture<br />

hidden, such as when your <strong>Sidewinder</strong> <strong>G2</strong> is acting as an<br />

“intrawall” between two sets <strong>of</strong> private addresses. External hosts<br />

will need to be reconfigured to point to the <strong>Sidewinder</strong> <strong>G2</strong> servers.<br />

Hosted split server DNS—In a <strong>Sidewinder</strong> hosted split server<br />

configuration, two DNS servers are hosted on the <strong>Sidewinder</strong> <strong>G2</strong>:<br />

one server (the external name server) is bound to the external<br />

burb and the other server (the "unbound" name server) is available<br />

for use by all internal burbs. Both servers are protected by the<br />

<strong>Sidewinder</strong> <strong>G2</strong> hardened OS, which is able to prevent attacks<br />

against them from penetrating your network.<br />

The security benefit <strong>of</strong> using a <strong>Sidewinder</strong> hosted configuration is<br />

the ability to hide the DNS entries on the unbound server from<br />

those who only have access to the external burb. External hosts<br />

will need to be reconfigured to point to the <strong>Sidewinder</strong> <strong>G2</strong> servers.<br />

Important: You must use hosted split DNS if you want the <strong>Sidewinder</strong> <strong>G2</strong> to hide your<br />

private IP addresses (via Network Address Translation).<br />

Note: Secure Computing recommends splitting the <strong>Sidewinder</strong> <strong>G2</strong> DNS servers when<br />

using hosted DNS.<br />

Domain Name System (DNS) 10-3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!