19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

All DNS clients, including those on the application gateway, must be<br />

configured in such a way that they always use the internal DNS server (e.g.<br />

using entries in the file /etc/resolv.conf).<br />

If an internal client asks for an internal computer, the internal DNS server is<br />

used. If an internal client or a client on the application gateway asks for an<br />

external computer, the internal DNS server is consulted, which in turn<br />

consults the external DNS server, which in turn consults the Internet, which<br />

then responds.<br />

An external client which asks for an internal host receives the restricted list<br />

from the external DNS server.<br />

<strong>The</strong> packet filter used must be configured in such a way that only the DNS<br />

service is permitted between the servers, i.e. DNS port 53 as the source and<br />

destination port. <strong>The</strong> approval of other ports (> 1023) is thus not necessary.<br />

net to be<br />

protected<br />

packet filter packet filter<br />

internal<br />

DNS enquiry<br />

private<br />

DNS server<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Dual-homed<br />

Application<br />

Gateway<br />

DNS-Abfrage<br />

des Gateway<br />

Figure 4: Configuration of the DNS servers<br />

Public<br />

DNS server<br />

exteral<br />

DNS enquiry<br />

insecure<br />

network<br />

<strong>The</strong> private DNS server is the primary DNS server for the protected<br />

network and passes enquiries about external computers to the public DNS<br />

server. <strong>The</strong> client on the gateway is configured in such a way that the<br />

private DNS server is first asked, which then may pass the enquiry on to<br />

the public DNS server. For external computers, the public DNS server is<br />

the primary DNS server for the protected network. However, it only<br />

contains the entries of the computers which are to be made known to the<br />

outside world.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!