Questions tagged [split-dns]

In computer networking, split-horizon DNS, split-view DNS, split-brain DNS, or split DNS is the facility of a Domain Name System (DNS) implementation to provide different sets of DNS information, selected by, usually, the source address of the DNS request.

In computer networking, split-horizon DNS, split-view DNS, split-brain DNS, or split DNS is the facility of a Domain Name System (DNS) implementation to provide different sets of DNS information, selected by, usually, the source address of the DNS request.

This facility can provide a mechanism for security and privacy management by logical or physical separation of DNS information for network-internal access (within an administrative domain, e.g., company) and access from an unsecure, public network (e.g. the Internet).

Implementation of split-horizon DNS can be accomplished with hardware-based separation or by software solutions. Hardware-based implementations run distinct DNS server devices for the desired access granularity within the networks involved. Software solutions use either multiple DNS server processes on the same hardware or special server software with the built-in capability of discriminating access to DNS zone records. The latter is a common feature of many server software implementations of the DNS protocol (cf. Comparison of DNS server software) and is sometimes the implied meaning of the term split-horizon DNS, since all other forms of implementation can be achieved with any DNS server software.

Reference - Wikipedia

58 questions
23
votes
3 answers

Naming a new Active Directory forest - why is split-horizon DNS not recommended?

Hopefully, we all know what the recommendations for naming an Active Directory forest are, and they're pretty simple. Namely, it can be summed up in a single sentence. Use a subdomain of an existing, registered domain name, and pick one that's not…
HopelessN00b
  • 53,385
  • 32
  • 133
  • 208
10
votes
1 answer

Are Windows 2016 DNS Policies / Split DNS possible on AD integrated zones with older DCs?

Windows Server 2016 supports DNS Policies, which provide support for split-brain DNS among other scenarios: You can configure DNS policies to specify how a DNS server responds to DNS queries. DNS responses can be based on client IP address …
8
votes
2 answers

Updates to a BIND dynamic zone that is shared between views delayed

Here's the quick and dirty: On BIND9 with a dynamic zone that's shared between views, doing a nsupdate, updating/creating/deleting a record will work fine if I query for that record from a client that falls into the same view I did the nsupdate…
enragedSquirrel
  • 83
  • 1
  • 1
  • 4
8
votes
4 answers

Zone transfers on a split-view Bind DNS system

I have a 2-server BIND 9 setup. Server A (the 'master' server) is properly setup with two views, one for local DNS clients (allowing recursive lookups for non-authorotive domains) and one view for the rest of the world, allowing only queries for…
Taco Scargo
6
votes
5 answers

Windows 10 Always On VPN, Split DNS, NRPT, and how to configure which DNS server is used?

Here's the setup: Windows 10 1803 clients Server 2012R2 RRAS server Always On VPN device tunnel setup per these instructions, with split tunneling. Device VPN only has routes to 1 DC/DNS server, and our configuration manager server, so it can be…
Grant
  • 17,671
  • 14
  • 69
  • 101
5
votes
2 answers

Microsoft DNS: Provide different answers per-src-subnet to same query - do I need full split horizon/brain?

I have a network with two vlans, both of which refer to my AD server(s) for DNS. Some servers on this network are multi-homed. Lets say we have the two subnets A: 192.168.7.0/24 and B: 192.168.5.0/24. Then we have a server whose hostname is…
Tom Newton
  • 4,021
  • 2
  • 23
  • 28
4
votes
2 answers

Can an authorative DNS server be configured to recurse when unable to find record locally?

Hopefully this is possible to do. The question Is it possible to configure a DNS server that is authorative for a given domain, to "fallback" and recurse via Forwarders / Root Hints when it cannot find the record locally? The scenario To give a…
4
votes
2 answers

Split-DNS on Windows

I have an internal network in which all services are registered under a internal domain (e.g.: coolcorp.io). When users connect to the VPN, I want them to be able to resolve the internal services in *.coolcorp.io, without having any other "public"…
3
votes
1 answer

Can I use server 2016 DNS policies to return alternative IPs but only for some records in a domain?

I need to provide a kind of DNS split-brain scenario with two key goals: "special" DNS clients (based on their subnet) must resolve certain A records in one domain to different IP addresses than the rest of clients all other records in the same…
3
votes
2 answers

Split DNS - Cleanest solution for easy maintenance?

We have split DNS set up for our domain, which causes internal clients to resolve different DNS records from external clients. As it is right now, the two zones are managed completely separately. For records that differ between internal and…
Moduspwnens
  • 747
  • 1
  • 7
  • 17
3
votes
1 answer

Windows DNS server: host a zone, but forward unknown entries

We have a split brain DNS scenario in our company where we have the same entries pointing towards different IPs. Example1: Internal DNS: email.company.net (A) 172.20.1.1 External DNS: email.company.net (A) 22.191.72.18 So email is just one of the…
3
votes
1 answer

BIND split-view DNS not working with zone transfer

I am setting up two DNS servers. One is on the firewall/router, the other is an internal server. I have lots of experience setting up DNS servers, so this problem is particularly perplexing. Machine setup Firewall external address:…
Barry Brown
  • 2,392
  • 4
  • 22
  • 23
2
votes
2 answers

PowerDNS Split Horizon Resolver

I've looked around the web for a solution and have found numerous threads with different suggestions. Most of which I've found has been using LUA on the resolver to return records. Other posts suggest using GEO-IP or Pipe backends. All of the…
Michael Moser
  • 219
  • 2
  • 4
  • 16
2
votes
2 answers

BIND9 DNS with external view inside the internal view

I'm planning a new BIND9 DNS Server with a special kind of view. We a have a lot of external zones and public IPv4 addresses. To keep things simple we have a subzone of our external domain just for the internal scope; something like:…
Vinícius Ferrão
  • 5,400
  • 10
  • 52
  • 91
2
votes
1 answer

Split DNS clarification

I need some clarification if I understood this correctly. I've been reading about Active Directory and naming my domain, and the reason Microsoft didn't suggest using external public domain was DNS Split. If I understood correctly (and please…
RidableCthulu
  • 145
  • 1
  • 6
1
2 3 4