19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

- Resolver<br />

<strong>The</strong> resolver is the program which sends the DNS queries to one of the<br />

defined name servers. A name server which is unable to perform name<br />

resolution can also act as resolver, sending the query to a name server<br />

outside the domain. Similarly the resolver interprets the responses received<br />

from the name server and sends information back to the programs which<br />

have requested it.<br />

DNS server configuration - initial steps<br />

With a NetWare 4.11 server, DNS is configured via UNICON.NLM. First of<br />

all DNS Client Access needs to be activated. This is done via Configure Server<br />

Profile - Manage Global Objects. At least one name server which performs<br />

address resolution must be listed. A maximum of three name servers can be<br />

entered. To speed up entry of a large address area and ensure that name<br />

resolution can be performed, the entries for the three name servers should be<br />

utilised. <strong>The</strong> sequence in which the name servers are listed determines the<br />

query sequence and should be determined in the manner which results in the<br />

fastest name resolution.<br />

<strong>The</strong> first name server can be the main DNS server of the authority or<br />

company. Even if this server cannot resolve every host outside its own<br />

domain, it allows host names to be resolved rapidly within the organisation.<br />

<strong>The</strong> second name server can belong to the Internet Service Provider (ISP),<br />

enabling access to a wider data pool of host names. This has the effect that due<br />

to the higher utilisation, the remoteness and the available bandwidth,<br />

resolution is usually somewhat slower than with the local name server. If<br />

redundancy of the local domain is a priority, then the server with the writeprotected<br />

copy of the DNS database (secondary name server) should be<br />

registered as the second name server.<br />

<strong>The</strong> third name server defined can be a so-called root server. This type of<br />

server holds the data for all the registered domains. A list of root servers can<br />

be obtained from ftp://rs.internic.net/netinfo/root-servers.txt.<br />

Configuration of the DNS server<br />

<strong>The</strong> configuration and administration functions for the Domain Name System<br />

are accessed by selecting Manage Services - DNS from the UNICON.NLM<br />

main menu. To set up a master database or a write-protected replica database,<br />

the Administer DNS menu option should be selected.<br />

<strong>The</strong> domains and zones for which the primary name server is authorised are<br />

entered by selecting Manage Services - DNS - Administer DNS - Manage<br />

Master Database - Delegate Subzone Authority from the UNICON.NLM main<br />

menu.<br />

<strong>The</strong> DNS database entries are entered via Manage Services - DNS -<br />

Administer DNS - Manage Master Database. With a standard implementation<br />

of DNS, the Start of Authority (SOA), which identifies the starting point for<br />

the authority of a zone within the DNS hierarchy, and the record type Name<br />

Server (NS) must be entered. <strong>The</strong> primary name server must receive entries<br />

for all the secondary name servers of the zone. Linking of this zone with the<br />

DNS hierarchy is achieved through name server entries for primary name<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Querying of the DNS<br />

server and interpretation<br />

of the responses<br />

Register three name<br />

servers<br />

Enter all the secondary<br />

name servers in the<br />

database

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!