19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

servers which possess authority for superordinate and subordinate zones. To<br />

ensure name resolution for the hosts in the zone, record type Address (A) must<br />

be entered for every terminal device to be addressed.<br />

<strong>The</strong> entries needed in record type SOA include the name and address of the<br />

zone supervisor. <strong>The</strong> default setting for this address is root..<br />

<strong>The</strong> settings for the synchronisation behaviour of the secondary name servers<br />

are also made in record type SOA.<br />

<strong>The</strong> refresh validity period determines the time within which a secondary<br />

name server continues to reply to queries from hosts after it has tried<br />

unsuccessfully to contact the primary name server. <strong>The</strong> shorter this time is set<br />

to, the lower the likelihood that the secondary name server will send invalid<br />

DNS entries and thus prevent name resolution. To make the system fail-safe,<br />

this time should not be set too short since, if the primary name server should<br />

fail, the Domain Name System for this zone will then no longer work. A<br />

compromise must be found for this parameter between the probability of being<br />

unable to resolve individual host names and - if too short a period is set - the<br />

probability of being unable to address any terminal devices by individual host<br />

names.<br />

<strong>The</strong> minimum caching interval determines the time for which information<br />

from queries is retained in the cache of the primary name server. If too short a<br />

time is selected, this can increase the load on the network where the same<br />

hosts are queried frequently and delay resolution of the host names into IP<br />

addresses. On the other hand, if too long a minimum caching interval is<br />

defined, this can result in out-of-date information being passed on.<br />

Connection to the external DNS hierarchy<br />

Queries involving host addresses outside the local domain are automatically<br />

executed as long as the DNS server is running. <strong>The</strong> DNS server receives<br />

information about the DNS hierarchy from the file<br />

SYS:ETC\DNS\ROOT.DB, which contains a list of name servers of the US<br />

Top Level Domains. Manage Services - DNS - Administer DNS - Link to<br />

existing DNS Hierarchy provides access to two different methods of building<br />

a direct connection to other domains, namely Link Direct and Link Indirect via<br />

Forwarder. If certain domains are accessed frequently, these procedures can<br />

speed up host name resolution.<br />

Checking of name servers<br />

<strong>The</strong> menu option Manage Services - DNS - Administer DNS - Query Remote<br />

Name Server allows checking of what information is held on other name<br />

servers as well as allowing one to determine whether a particular name server<br />

is responding to queries. In either case, the name or IP address of the server<br />

must be entered. <strong>The</strong> resource record type which is being interrogated and the<br />

domain from which the information is required must also be specified.<br />

Backing up the DNS database<br />

<strong>The</strong> DNS database should be backed up at regular intervals. Such backups can<br />

be used, for example,<br />

- to restore a DNS database which has become unusable,<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Direct connections to<br />

speed up name<br />

resolution

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!