How do I set up internal and external views in DNS

Setting up a test SNL10.6.8 server behind airport extreme.
Standalone server to run public DNS, iCal, Contacts and Web
I would like to include multiple views in etc/named.conf with statement match-clients{any;}; for public view and match-clients{127.0.0.1/32;10.0.0.0/8;}; for private view.  Server Admin won't let me do this.
I have two questions.
1.  Can I effectively secure this setup.
2. How do I do it?   Do I comment out ' include "etc/dns/publicView.conf.Apple" ' in etc/named.conf and add my own two views or do I use Server Admin to mangae the public view and zones and manually manage the internal zone?
Thank you for your help and advice. 

Linux and the BSDs (among other choices) are the full-power, deep-end-of-the-pool roll-your-own solutions. They're excellent choices for a number of application and network services configurations, and for cases with complex or tailored requirements.  The target market is tweakable and easily customized.  Mac doesn't aim there.
Having used and managed BIND on both Mac OS X Server and on other (non-Unix) servers, managing it on Mac OS X Server is simpler, though (as is often the case) you have to manage the server the way Apple expects you to.   The other servers I work with toss you into the BIND configuration files with a text editor, and while that's entirely feasible, it's not what I'd call user-friendly nor simple.  (See first paragraph.)
Running DNS at public servers (such as your ISP) and running a second set of DNS servers on your LAN is easily within reach of the Server Admin tool, and it means you don't have to be delegated, etc., for the public views, and it means your ISP owns securing your external DNS.
If you're accustomed to hand-managing and tweaking your DNS configurations, then Server Admin probably won't do all what you want, if you want to use any of the features of BIND9 past the subset that Server Admin allows you access to.  The question then becomes whether Server Admin does enough of what you need.
Running iCal via VPN is typical and folks that are not on the VPN can use the web interfaces or related, if you're not offering an "open" iCal connection through your firewall.
One other oddity you might want to consider.  Last I checked, BIND9 was also present in client.  Hand-managed.  That might give you a different option here.

Similar Messages

  • TEM How to diffrentiate b/w internal and external events

    Hi experts,
            How do i distinguish b/w internal and external events ? When i try to create an event always by default it shows as internal in the top right above planned and firmly booked radio buttons. How do i create an external event which is held outside the company ?
    please help...
    Thanks & regards,
    Pavan

    Hi Pavan,
    If you create a business event with resources, it is automatically considered an "internal" event -as you cannot plan resources OUTSIDE of your company-.
    If you create a business event w/o resources, than system gives you the option of internal/external selection.
    Regards,
    Dilek

  • Exchange 2010 and 2013 coexistence Internal and external URL

    Hi all,
    been reading alot of threads about Outlook anywhere and virtual directories in co-existence exchange 2010 and 2013.
    Still i dont get any smarter.
    Here is scenario:
    Exchange 2010
    Cas1
    Cas2
    Mailbox1
    Mailbox2
    Casarray is Exchange.casarray,com ( internal dns pointed to CAS1 in exchange 2010).Seems like by default both exchange 2013 cas servers are added to the casarray.
    Exchange 2013
    CAS+Mailbox
    Cas+Mailbox
    DNS
    mail.exchange.com pointing to VIP (kemp loadbalancer)
    Autodiscover ( pointed to same vip ,kemp load balancer)
    Outlook anywhere on all servers (2010 and 2013)
    Internal ( pointing to VIP on Kemp)
    External ( pointing to external IP,then it passes firewall that again passes to kemp)
    Problem we are having is when migrating users from Exchange 2010 - 2013.
    Users using Outlook 2010
    restart of outlook and mail  works fine.
    OWA works fine
    Active sync fails ( need to inherit permission of users AD object),wait couple of hours then mobile can sync again.)
    Users using Outlook 2013
    Outlook in disconnected status,only fix is to create new profile.
    OWA works fine
    Active sync fails ( need to inherit permission of users AD object),wait couple of hours then mobile can sync again.)
    Question is,what should be set for internal and external url (active sync,owa,ews)on 2010 and 2013 servers?
    Where is the config wrong?
    Thanks!
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

    Hi Martina,
    did the test as mentioned,even tried both CAS 2013 servers.Flush and registerdns didnt help.
    Still Outlook is Connected to the cas.exchange.as (which again Points to 1 of Exchange 2010 servers),
    Tried repair Outlook profile,no og.Only fix is to setup New account.
    Any more tips?
    thanks!
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

  • How to configure AD on windows 2012 server for Exchange 2013 internal and external email flow

    Dear Experts,
    I have to configure exchange 2013 on Windows server 2012 STD. Company has registered Static IP addresses and can get the MX record pointing to any of this Static IP.  
    The registered domain name is e.g.  contoso.com. 
    a. What should I use as domain name on AD? contoso.com or contoso.local
    b. Is it recommended to have two different servers  for AD and Exchange?
    c. What should be my connector settings for mail flow?
    d. how can I set 2 email servers in company for load balancing?

    Hi,
    a, I suggest use contoso.com as domain name. It is convenient to add urls into our certificate for internal and external mail flow.
    b, Recommended that installing AD
    and Exchange Server on two separate
    Servers. If Exchange Server downed unfortunately, it can prevent AD server from crushing at the same time.
    c, Found some articles for your reference:
    Configure Mail Flow and Client Access
    http://technet.microsoft.com/en-us/library/jj218640(v=exchg.150).aspx
    Configuring Outbound Mail Flow in Exchange Server 2013
    http://exchangeserverpro.com/configuring-outbound-mail-flow-in-exchange-server-2013/
    d, Load Balancing
    http://technet.microsoft.com/en-us/library/jj898588(v=exchg.150).aspx
    Hope it is helpful
    Thanks
    Mavis
    Mavis Huang
    TechNet Community Support

  • Internal and External different set of menu for ESS

    Hi
    We have 2 portal server - Internal and External. The Portal are being used not.
    We are planning to implement ESS now in Portal. We are planning to provide two different set of options when the same user access internally and externally.
    For example, User XYZ access internally he will get menus ABCDE but the same user access from external he only gets manu AB.
    If anyone has implemented with similar concepts or know how to do it technically, kindly advice.
    Thanks
    Yuva

    Let us assume we have 3 internal groups :
    internalGroup_1 -> Role A, Role B
    internalGroup_2 -> Role C, Role D,
    internalGroup_3 -> Role E,
    and 2 external group :
    externalGroup_1 -> Role A,
    externalGroup_2 -> Role B,
    We add similar user under a group. and then roles are assigned to groups. in above example Role A , Role B is assigned to internalGroup_1.
    We can have a single user id in which is attached to interalGroup_1, interalGroup_2, interalGroup_3 , externalGroup_1and interalGroup_2.
    When user logon to Internal portal he will see role A, B,C,D and E
    and when user logon to internal  poral he will see role A,B.
    provided A,B,C,D,E roles should exist in internal protal and role A,B exist in External portal. You can use transport roles from external portal to internal portal.

  • Internal and external mail setting

    I have 20 WinXP users connecting to my Xserve.
    I want to set up Mail so that only 3 Users can access mail both internally and externally from the office, the others I want to allow internal mail to each other but not to send/receive externally. Is this possible? If so how do I configure this behaviour?
    Regards
    Tony

    Can anyone assist with my previous posting?
    Can the functionality I want be achieved via the server or do I have to look foe alternative methods?
    Can anyone point me in the directon of info that will let me solve this issue?
    Regards
    Tony

  • How to I set an internal link in a PDF document using Preview?  After setting a link under the Tools/Annotations menu, the link doesn't work and no detailed instructions are provided.

    How to I set an internal link in a PDF document using Preview?  After setting a link under the Tools/Annotations menu, the link doesn't work and no detailed instructions are provided via the Help menu other than it showing the pull-down menu selection to make.

    No.  I am able to use the other features such as underlining, highlighting, adding rectangles and oval and save those changes.

  • All my hard drives (internal and external) have a small lock in the lower left corner of the icon and I don't have permissions to access. Permissions are set to 'Custom' in the get info window and I can't change them.

    All my hard drives (internal and external) have a small lock in the lower left corner of the icon and I don't have permissions to access. I have 3 user accounts set up and I cannot access any of them.   Permissions are set to 'Custom' in the get info window and I can't change them. Originally I had Snow Leopard installed on one hard drive and 10.5.8 installed on another.   I started to have some problems accessing data between them and so I tried changing the permissions on ONE hard drive partition.   The next thing I know, all my drives are locked (except the ones with the systems on them), the small lock appeared in the lower left corner of the drive icons and I don't have permissions to access any of them.   In the get info window, permissions are set to 'Custom' and I can't change them.

    There is suddenly a lock icon on my external backup drive!
    Custom Permissions

  • How to Setup RDS custom property when internal and external domain name space is different

    Hi All
    I am setting up RDS for customer
    My internal domain name is domain.local and my external domain is domain.com
    I came across below PowerShell cmdlets on some blogs because my internal and external name space are different
    Set-RDSessionCollectionConfiguration –CollectionName QuickSessionCollection -CustomRdpProperty “use redirection server name:i:1 `n alternate full address:s:remote.domain.com”
    In above command, remote.domain.com points to which host?
    Is it pointing to RD Session Broker
    OR
    Pointing to RD Session Host servers
    I am not sure what above command will do exactly ?
    Any help will be highly appreciated
    Thanks Best Regards Mahesh

    Hi,
    It all depends who is accessing the RDS Solution.
    If you have a large BYOD or large number of external users, it would be better to use a public certificate.
    Have a look at the following script which will simplyfy the configuration of the RDSH hosts with certificates.
    http://ryanmangansitblog.com/2014/05/20/rds-2012-rdsh-certificate-deployment-script/
    You can use a custom RDP property to hide the Session host names.
    Have a look at the following article on configuring certificates:
    http://ryanmangansitblog.com/2013/03/10/configuring-rds-2012-certificates-and-sso/
    Ryan Mangan | Ryanmangansitblog.wordpress.com | Help keep the forums tidy, if this has helped please mark it as an answer

  • How tro create a Internal and External repository?

    Hi Gurus,
    I am new to KM can someone tell me what is the prerequsities for creating Internal and External Repository?
    and give me the steps for creating Internal and External repository?
    Thanks in Advance,
    Dharani

    Hi Dharani,
    Refer this link:
    http://help.sap.com/saphelp_nw70/helpdata/en/69/d96b7da84611d5993600508b6b8b11/content.htm
    regards
    Parth

  • Delivery report shows status of Pending for external address. Email sent to both internal and external addresses.

    We have an Exchange 2013 on-premise server and seem to have an issue with emails sent to internal and external users at the same time.
    The issue came to light because someone sent an email to 44 recipients, of which one was internal. None of the external recipients received the email. I checked the delivery report in the EAC and found the internal email marked as 'Delivered' and all of
    the external ones marked as 'Pending'. I checked the queues and there were none. I did some testing and sent an email to just one of the external addresses on the list, it arrived. I tried sending the email again to all of the recipients, the external ones
    all showed 'Pending'. I tried it again, but this time excluded the internal email address and all of the 43 external emails were immediately delivered.
    So it seems that the issue only arises when we are sending to both internal and external addresses.
    I then tried a test email to one internal address and one external address. The Delivery report says that the internal address was delivered immediately, while the external address is 'Pending' and gives more information saying: 'Message delivery is taking
    longer than expected. There may be system delays. For more information, contact your helpdesk.'. To add further mystery to this, the email was actually delivered.
    So, I have two concerns:
    First is seems that some emails sent both internally and externally are only arriving internally. This is a huge problem because I don't know how many have been affected. There may be many lost emails we don't know about.
    Second, it looks like I can't trust the delivery report. It says pending for some emails which didn't arrive, but it also says pending for some which did arrive. That is no good at all.
    For info the server is running Windows Server 2012. I have run a Microsoft Update to check if there are any to apply and the only Exchange one is a spam filter update, which I doubt has any bearing but I will apply when I get chance.

    Hi Neil,
    According to the description, I find a related KB on Exchange 2010:
    https://support.microsoft.com/kb/2694474?wa=wsignin1.0
    It has the similar situation as yours.
    This issue occurs because a function in a message tracking component tries to obtain the information for the recipient instead of the external recipient.
    Please try to upgrade to the latest Exchange update to check whether this issue can be solved.
    Also please check whether Throttling has been set.
    Please run "Get-TransportService | fl" to check the MaxOutboundConnections parameter value.
    More details to see:
    Message throttling 
    http://technet.microsoft.com/en-us/library/bb232205(v=exchg.150).aspx
    Thanks
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Mavis Huang
    TechNet Community Support

  • Can I split my itunes music library between and internal and external hard drive?

    Is it possible to have music on the two different drives and still be able to make playlists from both drives to put on my ipod?  Here's my situation:  I'm using a Dell 32 bit computer running Vista Home Premium SP2 which I share with other users.  I have a large itunes library (40g+ of music only) that's starting to hog the hard disk space from other users. If possible, I would like to split off part of my itunes library to an external hard drive while still having access to the entire library for my ipod. Ideally I would like to have all my downloaded songs on both the internal and external drives so I'll have backups in case a drive fails, while putting all the music I have hard copies of solely on the external drive. Any help on how this can be done would be appreciated.

    If you manually manage your itues library, you can store parts of it on an external drive, or on an internal drive.  Just keep in mind that in iTunes that you must set a default location for iTunes to manage it's files, and that will be the default location for iTunes to store anything it downloads.  You would need to manuay manage moving things from there if tht is not where you want them stored.
    Perhaps a "better" solution would be for you to invest a little mone into 2 external drives.  One to hold your entire iTunes library, and the second to be your off-line backup of the first.  This is the method I have gone with and I like how it works for me.  My entire iTunes library is on an external (portable) 320GB drive.  Then, when iTunes is not running, I will clone my external drive onto a second drive I happen to have, this way if I have any failure of my primary drive, I lose at most about a weeks worth of content.  For me, I purchase little content during a week, but I do move a fairly large volume of podcasts.  With the entire library being on the external drive, if I ever have to swap to using my backup drive iTunes wil just think that it hasn't run and downloaded anything for a week, and all the "lost" content will be re-downloaded automatically.  This won't work for apps or purchased content, but for subscribed podcasts, it is great.

  • Backup internal and external hard drives-TC and offsite

    I now have Mavericks 10.9.3 on my iMac with a 2TB (1.25 TB used) internal hard drive.
    I also have some external drives attached to my iMac with older iPhoto libraries and other files (total file sizes 940 GB and 505 GB).  I primarily use Aperture now on my internal hard drive, but still access those iPhoto libraries on my external drives on occasion.  I have Time Machine backup my iMac internal hard drive on my 2TB Time Capsule regularly.
    My primary question is in regards to getting another copy onto a larger external drive that covers my internal and external drives so I can have a backup off-site.  Online backup services seem to always exclude external drives.  So a physical drive I can have offsite seems to be the best option.
    A year ago I changed the destination of my Time Machine backup to be on a 3TB external drive (backed up iMac internal hard drive and the two externals).  However, when I changed the destination of the backup back to the Time Capsule, the TM initiated a brand new backup (it did not recall that I had backed up prior to that on my Time Capsule).
    I want to backup monthly, if not quarterly for my off-site storage.  But, if every time I change the destination drive for TM, a new backup profile is created, it will overwork my drives unnecessarily.
    Is there a backup program or a process on "disk utility" I could run parallel to TM that I just use quarterly capturing only the changes/additions in those few months for both the internal and external hard drives?  Also, is there a way to add an external drive to my Time Capsule that is solely used to wirelessly backup the two externals on a regular basis (i.e. keep the internal 2TB drive backing up to the Time Capsule; and the external hard drive attached to Time Capsule via USB used as the backup drive for the external hard drives)?
    Summary:  I need to backup regularly to the local Time Capsule/additional external hard drive.  The data will come from my internal hard drive and my two external hard drives.  I also want to do quarterly backups of the additions/changes to all three drives to have on an offsite external drive that I manually backup to quarterly.  Any help is greatly appreciated.

    Carbon Copy Cloner is not on the App store.
    Correct.. it is not approved because Apple do not like the fact that CCC (and most likely superduper) which are the most popular backup software for Mac because it makes a bootable clone. Apple will never approve of that. But let me assure you that is the genius of it. If the internal disk fails, you simply boot from the external. It is $40 but you can use on all the computers in your home.
    CCC is a clone.. ie when it does the backup, any changes on the drive are changed on the clone. It does not work like Time Machine which simply piles up incrementals until the drive fills up. The idea of CCC is a backup of the drive as it exists at any point in time. TM btw is also not a reliable archive, ie it thins backups constantly.. so you should never rely on it to archive old versions.. but in the middle of a project it does a good job to keep various versions of your files. That is why I specifically said in my last post do not stop using it.
    and you can keep using the TC just for the internal drive.
    Keep TM running to the TC.. that will then keep a current hourly incremental of your drive. You can set CCC in a way which is a lot more flexible. ie backup just at the end of the day. There is no need for constant hourly backups. So to answer the second question.. you are still using your TC and TM.. but I suggest you only backup the internal drive.
    Please read a bit from forum expert Pondini on the value of clones and TM.
    http://pondini.org/TM/Clones.html
    That's why many folks use both Time Machine and a bootable clone, to have two separate, independent backups, with the advantages of both.  If one fails, the other remains.
    Now the ports issue.
    You can of course continue to use USB2. Just that moving large volumes around will be slow.. as doubtless you already know.
    On your particular Mac since you missed out on USB3 which is a pain.. you can buy a Thunderbolt to USB3 adapter like the belkin.
    http://www.belkin.com/au/p/P-F4U055/
    I suggested the Thunderbolt to Esata (it is an older interface and the adapter is rather cheaper but I hear more reliable.. check reviews for both).
    http://store.apple.com/au/product/H8875ZM/A/lacie-esata-hub-thunderbolt-series
    Sata is the interface of the hard disk.. Esata just means external sata.. so it is native and without conversion.
    I was merely suggesting ways to speed things up. But as long as you don't run CCC on more than daily basis then I think you will be fine just with USB 2. It will take a while on the day you do the swap over for the archive volume, but if you turn off the power saving in the Mac and leave it run overnight it should be able to do most of it.. you need to realise it will have to deep scan both the disks.. to compare files.. but CCC is based on Rsync and it is extremely fast and efficient. I am just not sure I know how long it will take to do. Anyway.. there is a plan.. tweak and adapt as you see fits your needs.

  • PP Internal and External  Operation

    Hi,
           I am marked one of my operation( say 40 th operation) in routing as 'Internal and External operation'. This operation is done both internally as well as externally.How I instruct system 60 Pc is processed externally and 40 Pc is processed internally incase of 100 PC of order qty.? More over how to confirm both of them???
    Edited by: Velmurugan S on Apr 29, 2008 7:44 AM

    Hi,
    I am not sure but it seems both the types are possible in this case. If you apply a control key with this setting, you may be able to either process it internally or create a PR against it.
    Note that its OR and not AND. So you may be able to process in one of the way and not both.
    For better understanding please check it in testing and tell us the results.
    Sumeet

  • Is it possible to make OSX see the internal and external HDD's as one large drive?

    Is it possible to make OSX see the internal and external HDD's as one large drive? For instance, hypothetically, could I have a Mac Mini Server with 2TB of internal storage and 2 external 4TB Thunderbolt HDD's, and make the OS see them all as one large 10TB drive?

    Yes it is possible to do this, but this is not recommended since a disconnection of the external drives would lead to a destabilized system. Its best to do this only with internal drives, or secondarily with only external drives that are set up separately from the boot drive.
    However, if you do wish to do this then you can combine any local set of volumes into one large "spanned" hard drive using Apple's CoreStorage volume management service. It does take a few steps to set up and requires use of the Terminal and Disk Utility. Here is a tutorial on how to do this: http://reviews.cnet.com/8301-13727_7-57550128-263/how-to-make-a-custom-corestora ge-drive-in-os-x/

Maybe you are looking for