define domain both for internal and external zones?

Barry Margolin barmar at alum.mit.edu
Sun Apr 6 05:15:14 UTC 2008


In article <ft9l98$18a5$1 at sf1.isc.org>, Gerry Reno <greno at verizon.net> 
wrote:

> Hi all,
>   I just setup bind 9.4.2 on F7 and created these views:
>      external; internal; localhost_resolver;
> 
>   In both the external and internal views I created these zones:
>      example.com
> 
>   In the internal version of example.com I mapped all the hosts and 
> service names to lan ips.
>   In the external version of example.com I mapped publicly available 
> hosts and services to public ips.
> 
>   My problem is that when my slave transfers the zones the external 
> example.com zone
>   is coming over with the correct names but they are mapped to internal 
> lan ips instead of the public ips that I listed in the zone!

I suspect this is being done by your firewall, not BIND.

> 
>   So my questions are these:  Is it not possible to have an internal and 
> external version of example.com?
>   If it is then is there something special that needs to be done for 
> this scenario?

If your firewall is a PIX, I think there's something like fixup_dns that 
can be disabled.  You don't need this on the firewall if the nameserver 
uses views.

-- 
Barry Margolin, barmar at alum.mit.edu
Arlington, MA
*** PLEASE don't copy me on replies, I'll read them in the group ***


More information about the bind-users mailing list