DNS - external DNS internal - Domainname?

Hello, I have the following problem:
Private IP network (192.168.0.0) behind router, which has a fixed external IP and an ADSL connection.
The Leo server on the internal network has a fixed IP: 192.168.0.20.
The Domain Name "firma.com" is hosted on a external provider, there is also a external web server running, which can be and should be accessible under "firma.com" and "www.firma.com".
I have set up a subdomain in the external provider’s DNS, "intranet.firma.com". This is resolving to the external IP of my router. The router is configured that it routes all requests from the external IP to the internal address "192.168.0.20".
The Mailxchange (MX) record also redirects on "intranet.firma.com."
And now the DNS server on the Leo-server? Which are the correct entries?
IP address: 192.168.0.20
subnet mask: 255.255.255.0
router : 192.168.0.1
Primary DNS: 192.168.0.20
DNS Secondary: I 192.168.0.1
Which has to be primary zone name: "firma.com" or "intranet.firma.com"? I mean, can there be "firma.com", when there is a external webserver which needs that name?
When I use "firma.com" for the Leo DNS and the server’s name is "intranet ", the it resolves to the internal server very well. But how can I get my externally hosted web "firma.com" or "www.firma.com", if I DNS server "firma.com" as the primary zone there? Which is the right configuration that I can send mails internal, external and from external? And use the external webserver as is?
Thank you
Willi

First using a 192.168.0.0/24 or 192.168.1.0/24 network on your LAN is a bad thing if you are going to use VPN later.
"I have set up a subdomain in the external provider’s DNS, "intranet.firma.com". This is resolving to the external IP of my router. The router is configured that it routes all requests from the external IP to the internal address "192.168.0.20". "
You can use this if you want but you probably don't want the mail to require a an address like:
<user/mailaccount-name>@intranet.firma.com do you? The MX pointer can use firma.com with an address of intranet.firma.com:
firma.com MX 10 intranet.firma.com
You could also look at intranet(.firma.com) as a hostname instead of a subdomain.
(Maybe you should use an other domainname internally: firma.private or firma.internal)
If you want to use the same domainname (firma.com) internally setup "all" the public names/IPs in the internal DNS and use only the server (private IP) DNS (with forwarders to your ISP DNS IPs) not the router DNS proxy for all internal machines.
If you want to run an intranet webserver why not call it intranet.firma.com and the public one keeps it's name www.firma.com.

Similar Messages

  • Follow up - DNS (internal domain has same name as external website)

    Hi,
    I am following up with on previous blog entry about resolving an domain internal name to an external website found here:
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/4d97325b-ff3a-4f46-ba6e-dc3f4ff978e1/dns-internal-domain-has-same-name-as-external-website
    On October 30, 2014
    HayashiTech provided a response suggesting the use of netsh interface portproxy on the DC's to resolve this issue. There has been no feedback to this suggestion and I am very curious what opinions are out there for this suggestion as it appears to be the
    best option provided yet.
    Thank you in advance as well for all the great guidance I have found provided by Ace and his followers.

    Interesting question. I've not seen that solution before, but having done a test on my lab setup it certainly seems to work as expected. Eg, using :
    netsh interface portproxy add v4tov4 listenport=80 listenaddress=dc1.abc.com connectport=80 connectaddress=www.abc.com
    on my DC where I've setup a working external domain name with the www record pointing to the website, and the non-www record pointing to the DC, requests to the non-www address are successfully being redirected to the www address (after confirming it didn't
    happen prior to adding the portproxy).
    So on the face of it that does look like a workable solution. I haven't used it myself in anger obviously, but the two downsides I can think of immediately to this solution are :
    1) This operates as a proxy, so unlike the IIS method that Ace mentioned where it would tell the client to go to the www address instead (so the client connects direct), this method keeps your DC acting as a middle man, eg all communications to that address
    go through your DC rather than direct from the client to the website. Depending on what they're doing on the website this may or may not be an issue for you.
    2) Since the client is continuing to connect to the DC throughout, if you ever did need the have something on the DC responding to port 80 then you could have issues. That said, according to
    https://technet.microsoft.com/en-us/library/cc731068(v=ws.10).aspx the portproxy listenaddress can be a FQDN rather than IP, so that could mitigate any issues there.

  • External and internal mikes are not automatically switching over either recording or on voice calls

    My laptop model name is HP Pavilion dv4-1100ea which is shipped with Vista Home premium 32 bits and has got service pack 1.
    Restored the laptop to factory setting since then I am having the following problems; I had the same problem when my laptop was brand new and whenever I reset the laptop to factory setting I get the following problems:
    1. External and internal mikes are not automatically switching over either in middle of the recording using sound recorder or while the call in progress on voice calls (skype):
       Using the sound recorder if I start recording the sound with external  mike  and in-between  recording if I  switchover from external mike to inbuilt mike and later on when I play back I can only hear the sound  up till where I used the external mike during recording, after the switchover to inbuilt mike I cant hear any sound.
       But if I start the recording with inbuilt mike and in between recording  if I plug in  the external mike and later on when I play back I can only hear the sound up till where I used the inbuilt mike during recording , after the switchover to external mike I cant hear any sound.
       So in brief both my external and internal mikes are working fine, only problem is that if I start recording (using sound recorder) or voice call with one specific mike, I have to continue with it till the end. I can’t switchover to another mike in between the conversation (voice call) or recording, if I do so, I have to select the mike manually in chat software but while recording I cant even select manually because in laptop, it takes the mike whichever is in current use as default mike in recording tab(sound window). The green tick automatically (in recording device tab) switches over according to the use of mike. Though the green tick in the recording tab is switching over automatically according to use of mikes, its not picking up the sound after switch over during recording.
    2. And also when I click on recording device tab in sound window and plug in external mike, though the green tick automatically switchovers from internal to external mike, while I speak both internal and external mikes volume meter respond to the sound inputs by rising and falling but if I take out external mike, green tick goes to internal mike and when I speak only internal mike volume meter respond to sound rising up and down not the external mike.
    To resolve the issue I have tried following steps with no luck:
    1.I have checked the mikes(internal and external) properties, the both mike shows to be enabled in general tab, in level tab the volume is set to 100 and in advanced tab , all options are selected.
    2. In device manager I have got only one audio driver named as “IDT High definition Audio CODEC”. I have uninstalled the audio driver and reinstalled it using scan for hardware option
    3. Uninstalled the audio driver in device manager and reinstalled the audio driver using recovery manager > advanced option> hardware driver re-installation.
    3. I have updated the BIOS(Insyde F.65, 12/02/2010).
    4. I tried to update the audio driver using below link but things went more worse so I did system restore (not factory setting though).
    http://h10025.www1.hp.com/ewfrf/wc/softwareDownloadIndex?softwareitem=ob-67051-1&lc=en&dlc=en&cc=us&...

    Sounds like you need to upgrade to the iPhone 5s
    The 5s has Touch ID
    You can unlock your phone with your finger instead of typing in a key code
    No swiping to unlock either, just touch the home button
    You can enrol multiple fingers as well
    Here is a video of it in action
    http://www.apple.com/iphone-5s/videos/#video-touch
    Or wait and see what iPhone 6 has to offer
    That being said, as desiel vdub posted if the phone is up to your face, the proximity sensor should turn the screen off
    And when you lower the phone turn it back on again
    Not sure about the phone locking when your on a call doesn't sound right

  • What's the easiest way to add storage to a mac mini. (1TB hard drive but only 32G of real storage). External device, internal or partitioning?

    What's the easiest way to add storage to a mac mini. (1TB hard drive but only 32G of real storage). External device, internal or is there some way to partition? I tried doing so but received a message that there wasn't enough free space to partition. Seems like a 1TB drive should have more storage than my Ipad

    Its worth confirming what free space you have on your drive: 
    go to:   Apple Menu > About this Mac >  More Info > Storage
    The bar chart shows how much free space there is on the drive:
    Please realise that partitioning does not create extra space so this wont help you.
    If your free space is less than 20 % you should get extra storage with an external USB or Firewire drive, any make or model will work.

  • What are policy firewall port should be permit between meetingplace web external and internal

    I deploy MeetingPlace Web Conferencing with SMA.
    1. What are policy firewall port should be permit between meetingplace web external and internal (web external on DMZ zone and web internal on internal zone)?
    2. Synchronized Globally Unique Identifiers (GUIDs) between internal and external Web Servers used firewall port?

    Hi,
    List of Firewall pots to be opened are mentioned in following document, you can refer your deployment type and open ports as mentioned.
    http://docwiki.cisco.com/wiki/Cisco_Unified_MeetingPlace_Release_8.5_--_System_Requirements_for_Audio-Only_Deployments
    http://docwiki.cisco.com/wiki/Cisco_Unified_MeetingPlace_Release_8.5_--_System_Requirements_for_WebEx-Scheduling_Deployments
    http://docwiki.cisco.com/wiki/Cisco_Unified_MeetingPlace_Release_8.5_--_System_Requirements_for_MeetingPlace-Scheduling_Deployments
    Regards
    Ronak patel

  • Employee external or internal?

    hi guys,
    i hv got a query..i am new to abap hr...how can i find out whther an employee is external or internal?
    this is related to joining correspondence which is sent to an attendee whenevr he is booked onto a course..so i need to specify the fee as ikost or ekost based on whether attendee is internal or external..
    response will be appreciated
    thanks

    Hi Mohit,
    Goto PP01 transaction and select H as the object type and select the Object ID of the external person for whom you want to take all the details.
    Select the Relationship from the Infotype screen and you can get all the information .
    Regards
    Vijay

  • Prob creating ABAP Proxy-Interface use external and interna msg definition

    Hi,
    I've created a service interface using external definition (message type for request and response), imported via WSDL file. However, while creating ABAP proxy in SPROXY, it gave the error message "Interface uses external and internal message definition". I searched through the forum, the questions were raised but no definite answer was found. Is it not possible to generate a proxy if there is any external definition used?
    Details of the error message:
    Message no. SPRX122
    Diagnosis
    In a message interface you can use messages from different sources:
    Message types and fault message types edited in the Enterprise Services Repository
    Messages imported into the Enterprise Services Repository (external definitions, RFC, IDoc)
    In the current message interface, message types from different sources have been used. Since messages from these different sources must be handled differently during proxy generation, such a mixture of messages within a message interface is not possible.
    System Response
    The interface cannot be generated.
    Procedure
    Change the interface definition accordingly in the Enterprise Services Repository.
    p/s: My external definition is actually derived from a ABAP FM web service. The reason why i used external definition is that i try to avoid the tedious steps of hard-coding all the data types for the request and response message types.
    Any help would be highly appreciated.
    - julius

    Hi Arvind,
    For technical reasons, proxy generation and the respective editors in the Integration Builder do not support the entire language range of XML schema and WSDL. For an overview of which language elements are supported, see the Excel spreadsheet in the SAP Service Marketplace at service.sap.com/xi ® Media Library ® Documentation: SAP XI 3.0 (SP11) u2013 Supported XML Schema and WSDL (EN).
    I couldnt find the above document in the service market place. Any hint to find it?
    Thanks.
    - julius

  • HT3986 can bootcamp be used with Windows install disk on an external drive (internal is broken) ?

    can bootcamp be used with Windows install disk on an external drive (internal is broken) ?

    With Boot Camp, you must install Windows onto in internal HDD (or SSD).  If you are referring that your internal Optical drive is broken, you might be able to install Windows from an external drive, but you might not.  I have heard varying levels of success with that.  I'm not sure what the official stance is, but I do know that if youe machine shipped with an internal optical drive, then you must use that to install Windows using Boot Camp and not swap it out for a "data doubler" and try to install from an external optical drive.

  • NAT external to internal

    i am having trouble with NAT. it is my first try at this and need some help, please. I have a 2610 with 2 Fastethernet connections. fa1/0 is internal 10.10.10.1/24
    fa0/0 is external 66.73.xx.xx/26
    i can succsefully go internal out to external with the ip nat inside source list 1 int fa0/0 overload command.
    what is the command to allow external to internal. thanks

    I think these should help depending on your exact scenario.
    Static NAT
    ip nat inside source {static {esp local-ip interface type number | local-ip global-ip}} [extendable | mapping-id map-id | no-alias | no-payload | redundancy group-name | route-map | vrf name]
    no ip nat inside source {static {esp local-ip interface type number | local-ip global-ip}} [extendable | mapping-id map-id | no-alias | no-payload | redundancy group-name | route-map | vrf name]
    Port Static NAT
    ip nat inside source {static {tcp | udp {local-ip local-port global-ip global-port | interface global-port}} [extendable | mapping-id map-id | no-alias | no-payload | redundancy group-name | route-map | vrf name]
    no ip nat inside source {static {tcp | udp {local-ip local-port global-ip global-port | interface global-port}} [extendable | mapping-id map-id | no-alias | no-payload | redundancy group-name | route-map | vrf name]
    Here is the link to the doc for NAT for more details on NAT
    http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124cr/hiad_r/adr_i2h.htm#wp1178184

  • DVD/CD unit external or internal?

    External or Internal which do you recomend?
    Is this the best internal?
    Apple/Pioneer DVR-109 (reports as a DVR-127D - see note below) DVD Recordable Drive
    16X DVD-R/+R, 6X DVD+R DL* Writer
    Thank you

    >Here in Mexico we look the 3 "Bs" -buena, bonita y barata.
    good, nice and cheap.
    Here we have a saying, too:
    "Good, nice, cheap. Pick any two - all three is not an option."
    Is it true if I clean the lens the problem -stopped recognizing DVDs and CDs- is fixed.
    I don't know the problem you're having with the existing drive to know whether cleaning it would fix the problem, but it's a good thing to try.

  • TNS Listener Poison Attack...externally or internally ?

    Hello all,
    with regrads to the below thread which mostly talks about Oracle Security Alert for CVE-2012-1675 "TNS Listener Poison Attack"....i just wanted to find out if this effect DB that are externally or internally....meaning 95% of our DB are in network(internally) behind our firewall....and rest of the 5% are outside our firewall facing the world wide web....so does this apply to both of just one ?
    Oracle TNS Poison vulnerability

    user097815 wrote:
    with regrads to the below thread which mostly talks about Oracle Security Alert for CVE-2012-1675 "TNS Listener Poison Attack"....i just wanted to find out if this effect DB that are externally or internally....meaning 95% of our DB are in network(internally) behind our firewall....and rest of the 5% are outside our firewall facing the world wide web....so does this apply to both of just one ?The attack is on the Listener itself - so if you want to prevent this attack, you need to secure that Listener, irrespective of its location.
    IMO, mandatory if you expose your Listener to an unsecured or public network (e.g. internet).
    As for Listeners running on your internal network - if this attack is used, securing your Listeners mean very little IMO. Because your internal network already needs to be compromised in order for the attack to occur. Which means you have far more serious problems then someone attacking your Listeners.

  • DNS Setup/View external website internally

    Greetings all - trying to set up a Mac server from scratch for the first time. Been managing one for a while but didn't actually set it up myself.
    I have the beginnings of DNS setup all squared away, but am still looking to figure out how to properly set up my website. Here's my setup. We used to have a joint Windows 2003/10.5 server environment. Windows handled Exchange and DNS, the Leopard box handled everything else (DHCP, web, file sharing, etc). We're transitioning everything to the Mac box in preparation for setting up Kerio MailServer and just to ditch the windows box.
    I own companyname.net - that domain is hosted externally by Network Solutions. It's forwarded to my static IP.
    Our old internal DNS was hosted by a Windows 2003 box - it had zones for companyname.ltd (the private internal domain) and companyname.net. companyname.ltd was the nameserver. There were two A records handling the website for internal clients - one with a blank name, and one with www. Both pointed to the IP of the Mac server (the current box that I'm transitioning everything to). Everything was hunky dory - internal pings to the web address went to the internal ip, externally it went to the external IP, and everything worked just great.
    So in setting up the new DNS on the Leopard box, here's what I have so far.
    Primary zone: companyname.net
    A Record: macpro : 192.168.1.3 (this is the name of the server)
    A Record: mail : 192.168.1.2 (our mail server)
    Alias : ichat : macpro.winstongroup.net
    The checkhostname thing works fine, Kerberos is up and running, as is Open Directory.
    Now, I do not know how to set up our website so that internal clients can view the external website. I tried creating an A record to the server for www, but then that overrides the macpro A record that is the host of the whole thing. I also tried creating A records to the external IP, but then when I pinged it just pinged once, then it seemed like the firewall kicked in and stopped it. I tried creating aliases to companyname.net but every time I did that, Server Admin kept adding on an additional companyname.net to the end of the name (so it would read like companyname.netcompanyname.net). That didn't make much sense to me.
    I'm sure there's other people who can view internally hosted sites from the lan - so any help would be very much appreciated!

    One minor other question. I prefer the url of our site to be companyname.net instead of www.companyname.net. So now, while www is set up as a server alias, it wouldn't direct to companyname.net, even though that URL was set up in the web services panel in Server Admin. I then created a new alias that was "companyname.net", without the trailing period so it was not a FQDM, directed it at the same web server, and everything seemed to work. Does that seem right - it's working, so it seems to be somewhat right at least!

  • DNS (internal domain has same name as external website)

    Our internal domain name is called "abc.com"  and our company website is called "abc.com".  I have created an "A" record that points to
    www.abc.com so staff can browse the website from within the office.  The problem is that if people enter "abc.com" from a web browser with the office it does not resolve in an efficient manner.  Can someone please
    help?
    Interflex

    Hi Interflex,
    I agree with Ace’s option 2 and 3 just like what I thought.
    I still consider the idea which Jorge provided about prevent register DC’s A record . This probably cause some un-expected issues,
    because this record is used for DFS and GPOs. So I don’t recommend this method.
    Meanwhile , I have thought as same as Ace’s second suggestion, if the environment or policy of your company allow deploy IIS on your
    DC server , I thought this could be a possible resolution.
    And I have a tips for your reference. If client’s browser is IE, by default, when you type web address in address bar,
    and press “ Ctrl + Shift +Enter “,IE will auto add Prefix WWW to the beginning of typed web address. In your case , users just type “abc” in address bar, and press  “ Ctrl + Shift +Enter “
    You can set this at “Prefix and Suffix option” which located at  “Internet Options”/ “General”
    Tab / ”language” button.
    Thank.
    Tiger Li
    Hi Tiger,
    I've actually found by default, just hitting Ctrl + Enter (without the shift key) puts in the 'www' and 'com.' but it only works for the 'com' TLD' by deffault. I guess you could add 'net' in the General tab, Language, suffix option to use ctrl-shift-enter,
    or whatever the actual internal TLD name is.
    Cheers!
    Ace
    Ace Fekay, MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003, Microsoft Certified Trainer, Microsoft MVP - Directory Services. This posting is provided AS-IS with no warranties or guarantees and confers no
    rights.

  • Afp:// not reachable internal with internal domainname, but works external

    i'm working on a OS X Server ML, its servername is 'server.domainname.private' and can i'm unable to mount afp volume with its own
    afp://server.domainname.private
    but
    afp://domainname.com
    is working!
    • > sudo changeip -checkhostname, says ="nothing to change"
    • no extra SRV record in DNS for _afpoverttcp._tcp
    • permissions given to a workgroup which can allready use the domainname.com as expected
    any clue how to solve, who the server users can reach and mount its own domain in intranet?

    Hi Oszillo,
    I a similar issue with my OS X server ML.
    The mobile user can log and sync to their home on the server (on closing and opening)  but when they work on the server himself (an imac), the server can't mount it's own afp.
    Did you found how to solve this issue ?

  • RD Session Broker + NLB doesn't work for external users (internal users on network/WAN are OK)

    Hi all,
    I have run into an issue as the title of this question suggests.
    So the senario is, I have (all Virtual):
    2x 2008 R2 Remote Desktop Servers
    1x 2008 R2 with Session Broker install
    I haven't configured any RD settings on the session broker server (i.e. RD virtual desktop, RD Gateway, etc) It's purely setup as the RD Connection Broker
    Each of the RD servers I have configured 2 NIC's. The 1st NIC is configured with NLB (NLB only setup for traffic on port 3389 all other traffic isn't handled by NLB). The other NIC is configured to be used only for session reconnection. I'm hoping this is
    the right configuration as it's how I have interpreted these guides:
    http://technet.microsoft.com/en-us/library/cc772418%28WS.10%29.aspx
    http://technet.microsoft.com/en-us/library/cc771300%28WS.10%29.aspx
    Please correct me if I have setup the servers incorrectly and what should be differently.
    I have setup the NLBs Cluster IP. A rule has been set on the router to make it available externally
    This worked fine with an old single RD Server (same IP as NLB Cluster IP, currently offline so no conflict) before the RD Farm was implemented. So I know the port forwarding is OK.
    So NLB and Connection Broker Load-Balancing work well for users inside the network. It spreads sessions evenly and there is no problem with DNS resolving the farm name etc. Sessions that are disconnected are reconnected to the same server, etc.
    Accessing the TS Farm from the external address isn't so successful
    Connectivity is random. Rarely it works, sometimes it gets to "initiating remote connection..." and then disconnects. It doesn't work more times than it does.
    So what do I need to do to get this working? Is there another component or something else that I need to configure to get it all working?
    I look forward you your help
    Thanks,
    Trent

    Hi Trent,
    If both the RD session broker and the NLB are working fine in
    the internal network, I suspect that there is something wrong with the external connection. I’d like to confirm the following questions to narrow down this issue:
    1.      
    Can you PING and telnet this RDS farm name when encountering the “disconnect” issue? For example: telnet farmname
    3389.
    2.      
    Can you individually connect to the RDS server when failing to connect it via farm name?
    3.      
    Did you configure any certificate on the RDS server or RD gateway server?
    4.      
    Do you get any event log when this issue happens on the server and client side? If yes, please let me know it word-by-word including the event ID.
    Thanks.

Maybe you are looking for