Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15738 > unrolled thread

Re: What is the proper way to delegate to a private / hidden sub-domain?

Started byGrant Taylor <gtaylor@tnetconsulting.net>
First post2020-05-06 17:03 -0600
Last post2020-05-06 20:56 -0400
Articles 2 — 2 participants

Back to article view | Back to comp.protocols.dns.bind

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: What is the proper way to delegate to a private / hidden sub-domain? Grant Taylor <gtaylor@tnetconsulting.net> - 2020-05-06 17:03 -0600
    Re: What is the proper way to delegate to a private / hidden sub-domain? "John Levine" <johnl@iecc.com> - 2020-05-06 20:56 -0400

#15738 — Re: What is the proper way to delegate to a private / hidden sub-domain?

FromGrant Taylor <gtaylor@tnetconsulting.net>
Date2020-05-06 17:03 -0600
SubjectRe: What is the proper way to delegate to a private / hidden sub-domain?
Message-ID<mailman.372.1588806226.942.bind-users@lists.isc.org>

[Multipart message — attachments visible in raw view] — view raw

On 5/6/20 4:12 PM, John Levine wrote:
> Since they can't access the root servers, how do you expect them to 
> do DNS lookups at all?
There is a copy of the root zone in the environment.

There is also enough net zone for the needed tests.

DNSSEC is obviously not in play with doctored zones in the labs.



-- 
Grant. . . .
unix || die

[toc] | [next] | [standalone]


#15739

From"John Levine" <johnl@iecc.com>
Date2020-05-06 20:56 -0400
Message-ID<mailman.373.1588812956.942.bind-users@lists.isc.org>
In reply to#15738
In article <mailman.372.1588806226.942.bind-users@lists.isc.org> you write:
>-=-=-=-=-=-
>
>
>On 5/6/20 4:12 PM, John Levine wrote:
>> Since they can't access the root servers, how do you expect them to 
>> do DNS lookups at all?
>There is a copy of the root zone in the environment.
>
>There is also enough net zone for the needed tests.
>
>DNSSEC is obviously not in play with doctored zones in the labs.

Oh, in that case, why don't you just put some adjusted NS entries in
your stub .net zone pointing at your internal name servers?  Seems a
lot easier than fooling around with routing.

[toc] | [prev] | [standalone]


Back to top | Article view | comp.protocols.dns.bind


csiph-web