Setting Up DNS - Making Sure I'm Not Running Split Horizon

Hello everyone - I'm wanting to make sure I am running my DNS correctly and that it isn't split horizon.
I purchased a domain name (johnsonsfromtyler.com). I have public "@" and "mail" A host names pointing to my public IP address, have a MX for johnsonsfromtyler.com pointing to mail.johnsonsfromtyler.com, and have a reverse lookup setup all via public DNS.
On my SLS running the private DNS I have the primary zone name set as johnsonsfromtyler.com. For the nameserver I have the zone johnsonsfromtyler.com. pointing to server.johnsonsfromtyler.com which has a static IP of 10.0.1.10. I also have a mail exchanger hostname of mail.johnsonsfromtyler.com with a priority of 10. I also have an alias for mail.johnsonsfromtyler.com pointed to server.johnsonsfromtyler.com. I also have forwarder IP addresses pointing to the OpenDNS servers.
I have my router setup to use the private DNS server located at 10.0.1.10 and the search domain as johnsonsfromtyler.com. server.johnsonsfromtyler.com is running DNS and all other server services.
So am I running DNS correctly and is this setup a split horizon setup? Also, do I need to have forwarder IP addresses pointing to external DNS servers?

As Mr Hoffman writes if your "reuse" a public IP domain name in an internal private IP only LAN DNS your are using a "split horizon" DNS (where did that "designation" come from?).
To reach pubic IP servers using the same domain name from your LAN using only the internal DNS, you need to put also the pubic IP servers in your internal DNS with their public IPs. The reverse zone for any "remote" public IPs that Server Admin creates should be removed to let the DNS responsible for that zone answer those lookups - probably not too important for most configurations though.
BIND views can be used to give answers to lookups depending on where (what IP) the query comes from. The same DNS could be setup with different views where public and private IPs are in separate views so that private name -> IP lookups only gets answered when the query comes from the private IP LAN. If you can have a different response (IP) for the same name -> IP lookup? - probably(?) - if the private IP view is listed before the public one in the DNS config.
And I think a DNS is always caching lookups (?) not depending on if forwarders is used or not. Forwarders can speed up lookups but can also make trouble if they stop working/starting refusing answering recursive lookup queries. Without forwarders the DNS has to go "the long way" via root DNS servers (you should update /var/named/named.ca regularly especially if not using forwarders).

Similar Messages

  • I have 2 websites and 1 IP address for my server, how do I set the DNS up?

    I am having trouble following the boards and the Server Admin instructions to make sure I can activate a website.
    IP address for the Snow Leopard Server on a mac mini
    Server Settings for Web has the 2 domain names listed pointing to the same IP address and same port 80.
    How do I point the DNS correctly to the domain I want to respond?  www.ziggythewinegal.com
    If you put the IP address in a browser, it returns the default domain which is just the apache/osx server page. 64.142.85.71
    If you put the first domain name in a browswer, it does the same. www.JoelQuigley.com
    How do I setup the DNS to www.ziggythewinegal.com which is in the folder WebServer>ziggy>index.php ?

    64.142.85.71 has an existing public DNS translation, so you'll be adding DNS CNAME (alias) records for the each of the additional hosts into your public DNS at WorldNIC DNS servers.
    Your local host either isn't running DNS, or it's running local DNS.  If it's running local DNS, then hopefully it's not running with the same domain name as your public DNS services; that you have an external DNS zone and an internal DNS zone, with an external DNS domain and an internal domain name.  If you are running DNS locally and are using the same domain name for internal and external DNS servers, then you'll also need to add the translation for the new web sites into your local DNS server configuration.
    Once the translation is added, add - as John Lockwood indicates - Sites into your web server. 
    The numbers of folders can vary.  Different sites may or may not be in the same folder, depending on what you're doing. Multiple ttraditional static HTML web sites are probably stored in separate folders.  A single site with several names can be in the same folder.  A web content management system (CMS) can be stored in one folder.
    If you have a firewall here (and you should), then you may need some additional steps.  Particularly if you're running NAT, and don't already have rules and port-forwarding enabled on the server.  Given it appears you're using mail with this server, there are likely some rules in place, though you'll need to confirm that port 80 TCP and possibly port 443 TCP are (also) being forwarded for your web services.
    Here is a write-up on adding what Apple calls Sites and what Apache calls virtual hosts.

  • Dbassist exception and netasst can not run

    Oracle 815 have been installed on turbo linux 2.2.10V4.0(CLASSPATH , LD_LIBARY_PATH are set both). But the netasst can not run. When I type netasst , linux give me noting the quit to xterm promot. And when run dbassist , it give a message like follow:
    JNLS Exception racle.ntpg.jnls.JNLSException Unable to find any National Character Sets. please check your Oracle installion.
    I have only choose one language(english) to install Oracle815.
    can anyone help me?
    Thanx.
    dflan

    thanks jmsalvo (John Salvo) for posting answer at http://homepages.tig.com.au/~jmsalvo/linux/oracle8i.html .
    dflan
    null

  • Help: Just finished shooting a wedding and Aperture crashes constantly during editing. All pic's in RAW and even after making sure I have the latest Aperture update, I have had to rebuild my library twice and "repair" does not seem to fix the issue. Help?

    Help: Just finished shooting a wedding and Aperture crashes constantly during editing. All pic's in RAW and even after making sure I have the latest Aperture update, I have had to rebuild my library twice and "repair" does not seem to fix the issue. Help?

    Well!
    If you have ThunderBolt, I would go with such for an External Working Drive, spinning platter or SSD depending on your budget
    This does not have to be huge just big enough to house your most current Jobs
    Once the Current Job is put to rest I would move it to a larger multi bay hard drive unit, USB or FireWire nothing fancy, no RAID, set up as one single Disk
    This would only be accessed when something is needed from a past Job so the connection does not have to be speedy
    The Drobo would be relegated to Vaults and backups
    You can set up a Vault on the Drobo to back up the External Working Library and then Reconnect it when you have moved the Library over to the other Enclosure
    This has worked for me pretty smoothly for a long while, but I have found over the years that one can not assume all people work in the same manner! :-)

  • My Iphone 4 will not send regular SMS messages. I have tried resetting my phone and by restoring and making sure i have SMS turned on. I receive them but can not send them. imessages work also. Plus my cellular data keeps randomly turning off. any ideas?

    My Iphone 4 will not send regular SMS messages. I have tried resetting my phone and by restoring and making sure i have SMS turned on. I receive them but can not send them. imessages work also. Plus my cellular data keeps randomly turning off. any ideas? Thank you

    Yes I have turned imessage off a number of times and that does not seem to he doing the trick, and it is not delivering them then I have to press on the photo and either chose try again or send as text message, I have had the setting on to not allow sending pictures as texts (so they can only send as imessage) since I got my phone in January and it has always worked until now, I have turned that off to allow me to send them as picture messages now but it's still not working over iMessage, I have also tried it using 3G and not wifi

  • How do I set up my airport express to make a connection with my Hp? I already have it set up for my mac laptop just not sure how to set it up so that theres also a connection with my Hp

    how do I set up my airport to make a connection with my Hp? I already have it set up for my mac laptop just not sure how to set it up so that theres also a connection with my Hp

    I set up my new HP Descjet 3054A . I had a problem becouse Apple give me CD as a driver. The thing was that CD wasn good for this printer becouse it was old software:) I had to go to Apple store so the specialist had to download me he wright driver. Becouse I didnt wannet to screw this up . When he downloaded driver I fired it up at house and thingworks perfect. The thing is when you download all the software from HP side . Then you have to connect your MAC to printer via USB . Fallow the instructions it should works. Worked for me. Good Luck!

  • RE6500 system time not set and, why set a DNS address?

    How do I set the RE6500 system time to current day if it's showing January 1970?  It is connected to the router on both frequencies and the extender output is working on both frequencies. I have set the RE6500 to a static address of 192.168.1.3 as the router address is 192.168.1.1.  In the RE6500 the default gateway is set to the router address of 192.168.1.1.  Is it necessary to set the DNS address in the RE6500 as the router is the default gateway?

    Hi Chadster766;  thanks for the prompt reply.  I tried using the external primary DNS address set in the router - saving and rebooting - and when that didn't work, I used the same IP address as the router 192.168.1.1.  That didn't work either; I did a warm re-boot of the computer after setting the DNS in the RE6500.  What am I missing or, should I reinstall the RE6500 and use the default DNS settings?  I'm using Windows 7 Sp1 and the RE6500 icon does not appear in Network, so it appears to be an issue between Windows and the RE6500.

  • Setting the DNS Suffix in Windows-2000:

    This is a solution for the frequent problem that arises during installation of iPlanet Application Server on Windows-2000 platform.
    <b>Problem:</b> After installation completes, the installation directory remains empty, there is no entry of iAS in "Windows start menu". It doesn't install anything.
    <b>Remedy:</b> Set the DNS Suffix.
    <b>Procedure:</b>
    Right click on <b>My computer</b> (icon on desktop or in windows-explorer), then click on properties, go to <b>Network identification</b> Tab, Click on properties, then click the more button, set the <b>Primary DNS suffix</b> (like india.sun.com), and also check the <b>Change Primary DNS suffix when domain membership change</b> check box, click all Ok buttons.
    <b>Note:</b>
    1. Make sure that it is added to the windows registry:
    Just run regedit and click on the <b>My Computer\HKEY_LOCAL_MACHINE\SYSTEM \ControlSet001\Services \Tcpip\Parameters</b> key, you will see the <b>Domain</b> key value set to your domainname, otherwise enter the domain name into this key value, and than <b>reboot the m/c</b>, and than reinstall the iAS. It should work.
    2. Make sure you are using static IP address.

    Thanks Sanjeev Agarwal

  • Two Xserves running 10.5 Server and setting up DNS...

    Hello.
    I have two Xserves (a G5 and a new Intel), both with fresh installs of 10.5 Server on them.
    Xserve #1 not going to be hosting any external services (FTP, web, email) and only housing internal, mission critical & confidential data (the server is set up with a mirror RAID on the OS drive as well as mirror RAID on the storage drives + nightly tape backups for offsite storage). Right now there are no plans for enabling iCal on this server as we're trying to keep the server as basic as possible (as we can afford zero downtime on this server), but if the initial setup of 10.5 requires configuration at first run to allow this type of thing, I'd like to deal with it now so as to keep my options open (as I know iCal on 10.5 requires Open Directory enabled).
    Xserve #2 is going to host FTP (for external clients) and internal file sharing for the design/production department (basically, for transferring files back and fourth between departments, so no data via this share will be "critical" as it's only temporarily on the server and will always exist in other locations). Even though this server will not host "critical" data, it will share the same backup/RAID scheme as Xserve #1.
    So, I'm curious as to how I set up DNS in this situation (so we can associate a domain name to our static IP address). We already have our main domain setup via 3rd-party hosting service (for web & email as we do not want to bring these services in-house), but we're purchasing a second domain that will be associated with company (via a static IP, so we can give a domain name instead of IP address for people needing to connect to the FTP server, make it easier for employees to remember the address for remote connections, etc.).
    Because Xserve #2 is going to be hosting FTP, would it make sense to setup DNS on this server and not set it up on Xserve #1? Also, and this could just be me being paranoid, but because Xserve #1 will be housing "critical & confidential" data I want to eliminate as much contact with the outside world as possible with this server, so this is another reason I feel Xserve #2 should have DNS running instead.
    Oh, and not sure if this makes any difference, but between the WAN and the LAN is a SonicWALL firewall and currently it deal with port forwarding, etc. depending on what services are being requested from the WAN (ie. remote machine connections, FileMaker remote connections, etc.).
    Any advice would be appreciated!
    Regards,
    Kristin.

    There's a couple of things in your post I don't understand:
    the server is set up with a mirror RAID on the OS drive as well as mirror RAID on the storage drives
    How are you doing this? Both XServes support only three internal drives and two mirrors require 4 drives. Where does the fourth drive come into play?
    I'm curious as to how I set up DNS in this situation
    There are numerous ways of doing this, but with a single static IP address your best bet is to leave DNS where it is - managed by your hosting provider. Just add a record in the domain zone (e.g. ftp.yourdomain.com) that has the IP address of the public interface your SonicWall firewall. You don't need a separate domain for this. You also don't need to setup internal DNS for this (although you may need internal DNS if you're running Open Directory.
    Because Xserve #2 is going to be hosting FTP, would it make sense to setup DNS on this server and not set it up on Xserve #1?
    Assuming you're referring to setting up a DNS server - use them BOTH. Make one of the servers the primary server (I'd pick the internal-only server for this) and set the other server to be a slave (so it copies all the zone data from the primary server). That way you have a replica of the data to provide additional resilience.

  • Making sure I understand release/retain correctly

    Let's say I do the following (foo starts out as some object):
    [foo release];
    // STUFF with foo
    [foo retain];
    As long as I'm not re-assigning foo, at the end of this I'll still have the same foo, right? I'm not risking losing foo during the //STUFF am I?
    I guess I'm making sure that my understanding of release is correct. If I release foo, it doesn't actually go away until all handles on it are gone. In other words, foo would have to be assigned to some other object in the //STUFF, or foo would have to go out of scope in the //STUFF (and presumably have a new foo created) in order for the actual original foo object to be deleted, right?
    Ok, edit for motivation, because that's kind of a dumb thing to want to do, right?
    The reason I want to do this is that lets say I have the following switch statement:
    switch (test)
    case 1:
    foo = [A alloc];
    [foo inita];
    break;
    case 2:
    foo = [B alloc];
    [foo initb];
    break;
    case 3:
    [foo setupc];
    break;
    case 4:
    f = [D alloc];
    [foo initd];
    break;
    It makes sense to release foo before the switch and retain it at then end. EXCEPT for case 3. So, I was thinking that if was safe to do what I proposed, it might make the code simpler.
    Of course I can just put a release/retain pair around each alloc/init, but that's a lot of replicated code...
    A [foo autorelease] and then the retain might just do the trick.
    Message was edited by: Brian Postow

    Brian Postow wrote:
    Let's say I do the following (foo starts out as some object):
    [foo release];
    // STUFF with foo
    [foo retain];
    As long as I'm not re-assigning foo, at the end of this I'll still have the same foo, right? I'm not risking losing foo during the //STUFF am I?
    There is no way to tell. If the retain count of foo was one just before the release, then all bets are off.
    I guess I'm making sure that my understanding of release is correct. If I release foo, it doesn't actually go away until all handles on it are gone.
    I'm not sure I understand your understanding. I wouldn't use a term like "handle" since that has a specific meaning that is different than "retain count". If you replace "handle" with "retain count", then you are correct.
    In other words, foo would have to be assigned to some other object in the //STUFF, or foo would have to go out of scope in the //STUFF (and presumably have a new foo created) in order for the actual original foo object to be deleted, right?
    I'm not sure what you are saying. Objective-C is not C++. A variable going out of scope means nothing in Objective-C. It isn't that complex. It keeps track of the number of times "retain" is called on the object (including the original, implicit "retain"). When the number of releases matches the number of retains, then the object is deallocated.
    Ok, edit for motivation, because that's kind of a dumb thing to want to do, right?
    The reason I want to do this is that lets say I have the following switch statement:
    switch (test)
    case 1:
    foo = [A alloc];
    [foo inita];
    break;
    case 2:
    foo = [B alloc];
    [foo initb];
    break;
    case 3:
    [foo setupc];
    break;
    case 4:
    f = [D alloc];
    [foo initd];
    break;
    You don't want to do that. Alloc-init is a set of operations. You can't spit them up. The object that "alloc" returns may not necessarily be the same object that "init" returns. "Alloc" may just return a global proxy object to do something more clever during the init.

  • DNS Issues, can't set static DNS server

    I have an Airport Extreme (which I'll call the router). It has an IPv6 tunnel (to Hurricane Electric), so it hands out IPv4 DHCP and announces an IPv6 network as well. The DNS servers configured on the router are OpenDNS'.
    My Apple TV 2 is connected via wired Ethernet to the router. It was using a DHCP address provided by the router, which made the DNS server the same address as the router. I wanted to manually set the DNS to use my ISP's, so that I can make sure the Netflix streaming issue I have is not a DNS issue.
    So I changed the Apple TV to a manual address, and set the DNS server to my ISP's DNS server (Apple TV can only have one DNS server? Odd.)
    After I save this, the Network page shows the correct manual IP, mask, and router, but the DNS Address is an IPv6 address (one that belongs to my network, but the entire address isn't visible), not the one I set. When I Configure TCP/IP again, and I reach the DNS Address page, the first digit of the existing address is "20", and the rest of the digits are "0". Interesting note as well: if I press Down, the number will increment to 19, and so on, but if I press Up, it changes to 0. Obviously the UI isn't designed for IPv6 addressing, but there's an IPv6 address in there nevertheless.
    Screenshots:
    http://www.flickr.com/photos/random_robin/5310011344/
    http://www.flickr.com/photos/random_robin/5310016288/
    I have tried to set the DNS Address multiple times now, and have restarted the Apple TV. The IPv6 DNS Address persists.

    After 16 hours of working i don´t have seen this easy solution. I had tried with Internet Explorer and Opera but finaly i have need to use Firefox.
    Thanks a lot to solve it.

  • Set Methods are not running

    I am writing my first jsp. I have a bean that I am wanting to use and my understanding is that if I put the following commands in, that all the set methods for my properties will run in the bean automatically as long as the names of the properties are the same as those on the form.
    <jsp:useBean id="MedicalBean" class="Project5.MedicalReimbursementRecord" scope="session"/>
    <jsp:setProperty name="MedicalBean" property="*"/>
    The form has a number of textboxes, each text box has a name of one of the properties in my bean. I put display in my bean and I know that it is never running any of the "set" methods for any of the properties. I know that it is indeed getting into my bean, as I have displayed which indicate that methods that I request are indeed running.
    I have not "ACTION" parameter on the FORM, but I have looked at the examples in Tomcat and they have forms which do not have an "Action". I don't think this is a problem, but maybe I am wrong about that. If I put in the statement of:
    <jsp:setProperty name="MedicalBean" property="GrpAcctNbr"/>
    Then I get the error "Cannot find any information on property 'GrpAcctMbr' in a bean of type 'Project5.MedicalReimbursementRecord'"
    So there must be something wrong with my setProperty statement, but what is it?
    Thanks in advance for your assistance.

    Can you show the relevant JSP code and set/get methods in the bean?
    Sometimes this error is caused by capitalization. e.g. a request param of "myName" calls setMyName(). Also, your bean must have a no arguments constructor.
    Also, if you don't specify an action,the form submits to the current URL so you should be ok. Are you sure that the JSP runs when the user submits the form?

  • How to set up DNS behind a NAT router...

    I am trying to configure DNS in Panther Server as the SOA for my domains and as a LAN name server. I've read several explainations about setting up DNS including technical document 106853 "How to set up DNS in a NAT environment" which says:
    Note: For Mac OS X Server 10.3 or later, you should use the Server Admin
    application to configure DNS and NAT. Please see the Network Services
    Administration Guide for additional information.
    Seeing how picky BIND is, this sounds like a good idea, except I can't configure views like that.
    Questions:
    1) What happens if I create an A record in my main domain for newmac.mydomain.com-->10.0.1.2? People outside the LAN can't get to it, right?
    2) Can I create really simple names for the LAN like newmac-->10.0.1.2?
    Thanks!

    You can use "system-config-network" command to configure your DNS configuration.

  • I want to delete my icloud-account from my iphone 5 and then register again, because I want to change my email-address/account name. What would be the steps to follow? How do I make sure I do not lose any information stored on/in my iphone 5?

    I want to delete my icloud-account from my iphone 5 and then register again, because I want to change my email-address/account name. What would be the steps to follow? How do I make sure I do not lose any information stored on/in my iphone 5?

    You would have to delete the existing iCloud account and create a wholly new one - you cannot change the @icloud.com email address of the one you already have.  To make a new one, you will also need an new AppleID as any AppleID can only have one iCloud account associated with it.
    Deleting the account will not delete anything off your device (if prompted for things like contacts, choose to keep them).  You will have to sync everything anew with the new account as you cannot move your sync'd content, your old backups or anything else from one iCloud account to another.  You will have to set up sync again and let it sync to the new account, and then make new backups to the new account as well.

  • After updating to 7.0.6 my iphone no longer shows in itunes. However it is recognised by my PC (windows 8) when click on my computer. I have tried reinstalling itunes and making sure the drivers are up to date. Has anyone else had this problem?

    Hi guys. After updating to 7.0.6 my iphone 5s is no longer showing in itunes. Strangley it is recognised by my PC (windows 8) when I click on my computer. I have tried reinstalling itunes and making sure the drivers are up to date, but this has made no difference. Has anyone else had this problem or does anyone have any advice? Thanks

    Device not detected in iTunes for Windows

Maybe you are looking for

  • Fuzzy horizontal lines around characters

    I'm also having a problem with the images I'm capturing. On the LCD screen off the camera the image looks fine, but when I'm capturing there are fuzzy lines around the subjects in frame. I've put the clip in the time line and changed the interlacing

  • Memory Leak in Flex Builder

    I created Services.mxml in the tutorial, set it as the default application file, and dragged the first component onto the design view screen, a label, when Flex Builder seems to get sluggish. Jumping out to the task manager revealed javaw.exe rapidly

  • How to put drop down list

    Hi All, I have added Z_field in Va01 Transaction. I want to put drop down list for that . Can you please suggest me how to do that. Regards Radha

  • I just signed up for the export pdf program and it just doesn't work.

    I used the program to transfer a pdf file into a document file. The new doc file left out some pictures, overran lines of type, completely misinterpreted caps and lowercase letters, and whole blocks of type overlapped or disappeared. Is there somethi

  • Names of Organizations or Societies for Developers

    Could somebody advice me on a few [top]names of Societies or Organizations for Software Developers ? I am looking to join a Society that is either national or global and which holds meetings once or twice a year, and which is not specific to a vendor