cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
671
Views
0
Helpful
1
Replies

DNS server in the DMZ

octroncisco
Level 1
Level 1

Hello,

We have a PIX firewall and We are thinking to move our external DNS server to our DMZ. We're using DNS Doctoring:

static (dmz,outside) DMZ_server1_public_IP DMZ_server1_private_IP netmask 255.255.255.255 dns

static (dmz,outside) DMZ_server2_public_IP DMZ_server2_private_IP netmask 255.255.255.255 dns

If I specify our DMZ hosts private IP address to the DMZ DNS server, It will work fine when an external user try to resolve a DNS name. For example, if an external user try to resolve our server1 DNS name, He will get the correct public IP address or He will get the private IP address specified in the DNS server?

Best Regards,

1 Reply 1

chris.cumbaa
Level 1
Level 1

This is more a DNS question than a firewall question.  The querying device would receive whatever IP address you have configured in the zone file.  If you have your private IPs configured, that's what it would get in response.

Review Cisco Networking for a $25 gift card