dns and nat

phn at icke-reklam.ipsec.nu phn at icke-reklam.ipsec.nu
Thu Jul 25 17:08:00 UTC 2002


Ralf Hanl <rhanl at hit-consulting.net> wrote:

> Peter,

> thanks for your answer. But this problem appears not via the internet,sits a
> intranet between two different companies.

That was my idea. Create a VPN to route the two sites. The only catch
is that they use different rfc1918 networks.

And the VPN should only be used for traffic between these sites, 
everyting else should go throu yoy ordinary nat device.



> any further ideas ?

> thks
> Ralf

> -----Ursprüngliche Nachricht-----
> Von: bind-users-bounce at isc.org [mailto:bind-users-bounce at isc.org]Im
> Auftrag von phn at icke-reklam.ipsec.nu
> Gesendet: Donnerstag, 25. Juli 2002 10:29
> An: comp-protocols-dns-bind at isc.org
> Betreff: Re: dns and nat



> Ralf Hanl <rhanl at hit-consulting.net> wrote:

>> I have to different networks with a nat-router and a few transfer networks
>> between them. I want to setup a primary dns on one network and a secondary
>> on the other.

>> Now I expect the following problem: Because of the NAT one Maschine has
> two
>> different IPs, a physical and a natted ? If I configure one name with two
>> IPs in the a-records, I think, I can reach something like round robin, but
>> in my envirement, name resolution is time critical. Is there a better
>> solution.

> Create a VPN solution and use private addresses for your nameservers. This
> will make the nameservers know each other via their private address.


>> Ralf




> --
> Peter Håkanson
>         IPSec  Sverige      ( At Gothenburg Riverside )
>            Sorry about my e-mail address, but i'm trying to keep spam out,
> 	   remove "icke-reklam" if you feel for mailing me. Thanx.



-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


More information about the bind-users mailing list