Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15727 > unrolled thread

Re: What is the proper way to delegate to a private / hidden sub-domain?

Started byGrant Taylor <gtaylor@tnetconsulting.net>
First post2020-05-06 14:10 -0600
Last post2020-05-06 16:21 -0400
Articles 2 — 2 participants

Back to article view | Back to comp.protocols.dns.bind

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: What is the proper way to delegate to a private / hidden sub-domain? Grant Taylor <gtaylor@tnetconsulting.net> - 2020-05-06 14:10 -0600
    Re: What is the proper way to delegate to a private / hidden sub-domain? "John Levine" <johnl@iecc.com> - 2020-05-06 16:21 -0400

#15727 — Re: What is the proper way to delegate to a private / hidden sub-domain?

FromGrant Taylor <gtaylor@tnetconsulting.net>
Date2020-05-06 14:10 -0600
SubjectRe: What is the proper way to delegate to a private / hidden sub-domain?
Message-ID<mailman.359.1588795849.942.bind-users@lists.isc.org>

[Multipart message — attachments visible in raw view] — view raw

On 5/6/20 1:44 PM, Bob Harold wrote:
> Good questions.

:-)

> I think one possibility (to avoid anycast) is to have an internal and
> external view for the "example.net" zone, so it can delegate the lab
> zones to different servers internally and externally.

But how do you do that if the internal and external views are on 
different servers with completely different IPs?

I ask because now you're back to the same issue, just at the parent 
domain:  How does the net zone delegate to different example zones 
depending on if the client is internal or external.

I don't see any options that avoid anycast.

> But that can make the "example.net" zone harder to manage. It would
> be easier to have a split view for "split.example.net" and lab zones 
> "lab#.split.example.net", if the extra level was acceptable.
Please elaborate on what you mean by "split view" hear.  I'm used to 
"split view DNS" being tantamount to what I would use views for.  Which, 
as previously stated, won't work in this case because the different 
views are hosted on different servers.



-- 
Grant. . . .
unix || die

[toc] | [next] | [standalone]


#15728

From"John Levine" <johnl@iecc.com>
Date2020-05-06 16:21 -0400
Message-ID<mailman.361.1588796493.942.bind-users@lists.isc.org>
In reply to#15727
In article <mailman.359.1588795849.942.bind-users@lists.isc.org> you write:
>> I think one possibility (to avoid anycast) is to have an internal and
>> external view for the "example.net" zone, so it can delegate the lab
>> zones to different servers internally and externally.
>
>But how do you do that if the internal and external views are on 
>different servers with completely different IPs?

Don't Do That.

>I ask because now you're back to the same issue, just at the parent 
>domain:  How does the net zone delegate to different example zones 
>depending on if the client is internal or external.
>
>I don't see any options that avoid anycast.

This really seems like ordinary split horizon DNS.

-- 
Regards,
John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. https://jl.ly

[toc] | [prev] | [standalone]


Back to top | Article view | comp.protocols.dns.bind


csiph-web