Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


August 27, 2008

Split-Brain DNS

This slick configuration resolves locations correctly from both inside and outside of your local network
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Reader Feedback on "Split-Brain DNS"

You can now test your split-brain configuration from your workstation. But before you do, make sure to flush your DNS cache by entering the following from a command prompt: ipconfig /flushdns Type www.mydomain.com into your browser, and your site should load. Neat, isn’t it?

You can add additional hosts to your newly created zone for any other resources, such as a mail server or a terminal server, that you want to access by the same name both internally and externally.

Divide to Conquer
You can modify the solution presented above by having your internal AD DNS servers answer queries only for AD resources and forwarding all other requests to another set of internal DNS servers. This other set would contain your private IP records for mydomain .com and recursively answer queries for all other domains. This type of segregation can help both with risk mitigation and administration delegation because the AD DNS servers would be separate from the DNS servers you use for split-brain resolution.

An alternative to split-brain DNS would be to use a third-party solution at the edge of your network that can rewrite the IP addresses returned in packets containing DNS data. For example, Cisco’s PIX and ASA appliances have a feature called DNS Doctoring that performs such rewrites. All of these methods are fairly easy to execute, but you should still try them in a test environment before making changes to your production environment. Happy querying!

End of Article

   Previous  1  [2]  Next  


Reader Comments
Reader Jeff Krull contacted Michael Dragone with this question about his organization's split-brain DNS configuration: "Mike - Saw your article in Windows IT Pro. Don't know if you can answer this one regarding split-brain DNS config. We have a split-brain dns zone, which is the root of our AD forest. Since it's an ad-integrated zone, when performing an nslookup on the zone for mycompany.com, DNS returns a list of DNS Servers (which are the DCs). That's just great for AD and associated GPO processing, etc.

When a user browses the domain internally using a browser, we can't resolve the company's web site (i.e. companyname.com times out) because the DCs don't run IIS to redirect the query, nor do we want our DCs running IIS. Externally, this is not a problem because the DCs aren't listed in the external zone. Any ideas on how to resolve this issue whereby internal users don't have to use www.mycompany.com internally to reach our web site?
Thanks, Jeff
Check out the "Reader Feedback" sidebar (click the link above the article) for the complete conversation between Jeff and Mike. And if you have feedback about this article, post a comment or email it to Mike Dragone (click his byline). Windows IT Pro authors like hearing from readers--and really do respond!

AnneG_editor September 25, 2008 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...


Related Articles Deconstructing DNS

DNS Configuration Errors Breed AD Horror

Windows Server 2003 DNS

Solving DNS Problems

Networking Whitepapers Should Your Email Live in the Cloud?

Meeting Compliance Objectives in SharePoint

Email Controls and Regulatory Compliance

Related Events Troubleshooting Active Directory

Managing IT Across Multiple Locations

Check out our list of Free Email Newsletters!

Active Directory (AD) eBooks The Essentials Series: Active Directory 2008 Operations

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement