Win2k delegation behind firewall.

Kevin Darcy kcd at daimlerchrysler.com
Tue Aug 22 21:50:50 UTC 2000


Upgrade IMMEDIATELY. 8.2.1 has a root-level exploit.

As for your question, looks like you've built your network in a NAT-centric
way and now you've run out of the resources necessary to support that
architecture, given Win2K's requirements. I don't know of any DNS magic
shovel that can help dig you out of that hole. Maybe you need to
re-architect. Sorry if that sounds harsh, but I absolutely *despise* NAT...


- Kevin

Wade Grant wrote:

> I have a firewall doing NAT between my WAN and Internet points.   On the
> outside I have my Primary DNS with 8.2.1 with my real addresses. On the
> inside I am using the 10.x.x.x network broken up into multiple B and C
> networks and a 172.16.x.x. network.  At 172.16.1.2 Primary inside DNS
> and at 172.16.1.1 a secondary.  My problem is that I have servers within
> the 10.x.x.x network that want to  be able to dynamic the DNS within
> their own subdomains with Win2k servers and use their Win2k servers for
> DNS queries.  I dont want to update the outside DNS b/c of traffic
> through the firewall and the NAT pool which changes the inside to
> outside translation constantly(not enough real IPs to static every
> machine).
> Any Help would be appreciated.
> Wade Grant
> wgrant at mde.k12.ms.us






More information about the bind-users mailing list