root server queries

phn at icke-reklam.ipsec.nu phn at icke-reklam.ipsec.nu
Thu Oct 24 11:10:45 UTC 2002


Chris Hurt <chris.hurt at monsanto.com> wrote:
> Hi,

> I have a bunch of internal dns servers that use forwarders for external
> resolution.  The network folks have brought an issue to me for resolution.
> The issue is that my internal servers occasionally make queries to the root
> servers (which of course get dropped at the firewall).  Can't I just create
> my own internal root servers (that would only have delegation info for our
> internal domain) to avoid this traffic or will this break something?

If you use internal root's your internal servers won't be able to 
resolve outside names.

The alternative is to configure or replace the offending 
nameservers, or accept that some packets will be cought in the
firewall.


> Thanks,
> Chris

> P.S.  Running BIND 9.2.1




-- 
Peter Håkanson         
        IPSec  Sverige      ( At Gothenburg Riverside )
           Sorry about my e-mail address, but i'm trying to keep spam out,
	   remove "icke-reklam" if you feel for mailing me. Thanx.


More information about the bind-users mailing list