RFC ?

phn at icke-reklam.ipsec.nu phn at icke-reklam.ipsec.nu
Mon Jul 22 17:49:42 UTC 2002


A Record <subdomain at 127.0.0.1.easynews.com> wrote:
> Can any one tell me the name of the RFC that mentions the prohibiting of A
> records pointing to private IP addresses.

There is no such RFC. 

RFC1918 however prohibits showing A records for rfc1918 addresses to
Internet :

P.6 bottom :
If an enterprise uses the private address space, or a mix of private
   and public address spaces, then DNS clients outside of the enterprise
   should not see addresses in the private address space used by the
   enterprise, since these addresses would be ambiguous.  One way to
   ensure this is to run two authority servers for each DNS zone
   containing both publically and privately addressed hosts.  One server
   would be visible from the public address space and would contain only
   the subset of the enterprise's addresses which were reachable using
   public addresses.  The other server would be reachable only from the
   private network and would contain the full set of data, including the
   private addresses and whatever public addresses are reachable the
   private network.  In order to ensure consistency, both servers should
   be configured from the same data of which the publically visible zone

That is you are encourgaged to apply "split-dns" where your 1918
addresses _may_ be visible inside your network but must not be 
visible fro outsiders.


> TIA,

> A.



-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


More information about the bind-users mailing list