PC Review


Reply
Thread Tools Rate Thread

DNS does not resolve NAT address

 
 
Jimme Quinn Ross
Guest
Posts: n/a
 
      23rd Sep 2004
Q.) How can I set up our internal DNS so that our public
name is resolved to our private IP address?

Info.
We have an internal DNS that works fine inside the firewall

The public address for our Web site is not resolved
because we can't use NAT'd address' internally.

Jimme
 
Reply With Quote
 
 
 
 
Kevin D. Goodknecht Sr. [MVP]
Guest
Posts: n/a
 
      24th Sep 2004
In news:291401c4a1ac$e856dc70$(E-Mail Removed),
Jimme Quinn Ross <(E-Mail Removed)> commented
Then Kevin replied below:
> Q.) How can I set up our internal DNS so that our public
> name is resolved to our private IP address?
>
> Info.
> We have an internal DNS that works fine inside the
> firewall
>
> The public address for our Web site is not resolved
> because we can't use NAT'd address' internally.
>
> Jimme


By creating a zone for the web site name, e.g. www.example.com then in that
zone, create a new host leave the name field blank and give it the IP of the
Web server.
This way your DNS server only resolves www.example.com to the internal IP
and all other names in example.com will be forwarded.

--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


 
Reply With Quote
 
Guest
Posts: n/a
 
      24th Sep 2004
Fantastic! It worked! Thanks you very much.

It resolved nyslrs.state.ny.us fine, but when I added a
zone named public.leginfo.state.ny.us it did not resolve.
I will need to add several more but do not have the names.

Any thoughts?

Jimme

>-----Original Message-----
>In news:291401c4a1ac$e856dc70$(E-Mail Removed),
>Jimme Quinn Ross <(E-Mail Removed)> commented
>Then Kevin replied below:
>> Q.) How can I set up our internal DNS so that our public
>> name is resolved to our private IP address?
>>
>> Info.
>> We have an internal DNS that works fine inside the
>> firewall
>>
>> The public address for our Web site is not resolved
>> because we can't use NAT'd address' internally.
>>
>> Jimme

>
>By creating a zone for the web site name, e.g.

www.example.com then in that
>zone, create a new host leave the name field blank and

give it the IP of the
>Web server.
>This way your DNS server only resolves www.example.com to

the internal IP
>and all other names in example.com will be forwarded.
>
>--
>Best regards,
>Kevin D4 Dad Goodknecht Sr. [MVP]
>Hope This Helps
>===================================
>When responding to posts, please "Reply to Group"
>via your newsreader so that others may learn and
>benefit from your issue, to respond directly to
>me remove the nospam. from my email address.
>===================================
>http://www.lonestaramerica.com/
>===================================
>Use Outlook Express?... Get OE_Quotefix:
>It will strip signature out and more
>http://home.in.tum.de/~jain/software/oe-quotefix/
>===================================
>Keep a back up of your OE settings and folders
>with OEBackup:
>http://www.oehelp.com/OEBackup/Default.aspx
>===================================
>
>
>.
>

 
Reply With Quote
 
Kevin D. Goodknecht Sr. [MVP]
Guest
Posts: n/a
 
      24th Sep 2004
In news:311601c4a24d$ae172370$(E-Mail Removed),
(E-Mail Removed) <(E-Mail Removed)>
commented
Then Kevin replied below:
> Fantastic! It worked! Thanks you very much.
>
> It resolved nyslrs.state.ny.us fine, but when I added a
> zone named public.leginfo.state.ny.us it did not resolve.
> I will need to add several more but do not have the names.
>


Did you create the blank record with this IP address?
public.leginfo.state.ny.us. 86400 IN A 68.236.129.8



--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      27th Sep 2004
In news:%23$(E-Mail Removed),
Kevin D. Goodknecht Sr. [MVP] <(E-Mail Removed)> made a post then I
commented below
> In news:311601c4a24d$ae172370$(E-Mail Removed),
> (E-Mail Removed)
> <(E-Mail Removed)> commented
> Then Kevin replied below:
>> Fantastic! It worked! Thanks you very much.
>>
>> It resolved nyslrs.state.ny.us fine, but when I added a
>> zone named public.leginfo.state.ny.us it did not resolve.
>> I will need to add several more but do not have the names.
>>

>
> Did you create the blank record with this IP address?
> public.leginfo.state.ny.us. 86400 IN A 68.236.129.8


I think that may be his WAN IP address of his NAT. Wasn't he asking for the
internal address?

--
Regards,
Ace

Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.

This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services

Security Is Like An Onion, It Has Layers
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
--
=================================


 
Reply With Quote
 
Kevin D. Goodknecht Sr. [MVP]
Guest
Posts: n/a
 
      27th Sep 2004
In news:(E-Mail Removed),
Ace Fekay [MVP] <PleaseSubstituteMyActualFirstName&(E-Mail Removed)>
commented
Then Kevin replied below:
> In news:%23$(E-Mail Removed),
> Kevin D. Goodknecht Sr. [MVP] <(E-Mail Removed)> made
> a post then I commented below
>> In news:311601c4a24d$ae172370$(E-Mail Removed),
>> (E-Mail Removed)
>> <(E-Mail Removed)> commented
>> Then Kevin replied below:
>>> Fantastic! It worked! Thanks you very much.
>>>
>>> It resolved nyslrs.state.ny.us fine, but when I added a
>>> zone named public.leginfo.state.ny.us it did not
>>> resolve. I will need to add several more but do not
>>> have the names.
>>>

>>
>> Did you create the blank record with this IP address?
>> public.leginfo.state.ny.us. 86400 IN A
>> 68.236.129.8

>
> I think that may be his WAN IP address of his NAT. Wasn't
> he asking for the internal address?


You're so right, I guess there's no way for me to tell him that.


--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      28th Sep 2004
In news:(E-Mail Removed),
Kevin D. Goodknecht Sr. [MVP] <(E-Mail Removed)> made a post then I
commented below
>>
>> I think that may be his WAN IP address of his NAT. Wasn't
>> he asking for the internal address?

>
> You're so right, I guess there's no way for me to tell him that.


Ok, I wasn't sure. That's what I thought. I guess if he doesn't post back,
hope he figures it out!
:-)


Ace


 
Reply With Quote
 
Ed Horley
Guest
Posts: n/a
 
      28th Sep 2004
Are you using the internal DNS server to answer external queries? In other
words, you have a NAT mapping on your firewall that allows external clients
to connect to your internal DNS server? That seems to be what you are
saying.
If that is the case, your entries on your internal DNS server are for
external IP addresses (not rfc 1918 space) and will only reply back with
those external IP addresses. If your firewall does aliasing (the Cisco PIX
does this) then you can tell the firewall to "lookup" the NAT translation
for the Public IP address and use the internal address when it gets hit with
the request. It will then redirect the traffic to the webserver after it
fixes the ip addresses in the packets.
Other options are to create a different DNS server for your internal client
machines or use a host file to define your internal website ip address.
First is better, second will work but is a pain to manage over the long
haul.

Regards,
Ed Horley

"Jimme Quinn Ross" <(E-Mail Removed)> wrote in message
news:291401c4a1ac$e856dc70$(E-Mail Removed)...
> Q.) How can I set up our internal DNS so that our public
> name is resolved to our private IP address?
>
> Info.
> We have an internal DNS that works fine inside the firewall
>
> The public address for our Web site is not resolved
> because we can't use NAT'd address' internally.
>
> Jimme



 
Reply With Quote
 
Jimme Quinn Ross
Guest
Posts: n/a
 
      4th Oct 2004

>-----Original Message-----
>In news:(E-Mail Removed),
>Kevin D. Goodknecht Sr. [MVP] <(E-Mail Removed)> made

a post then I
>commented below
>>>
>>> I think that may be his WAN IP address of his NAT.

Wasn't
>>> he asking for the internal address?

>>
>> You're so right, I guess there's no way for me to tell

him that.
>
>Ok, I wasn't sure. That's what I thought. I guess if he

doesn't post back,
>hope he figures it out!
>:-)
>
>
>Ace
>
>
>.
>He did! Well, sort of. The entry I made is now working. I

need to learn more about DNS. Thanks again for your help!

Jimme
 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      5th Oct 2004
In news:36d401c4aa2b$b7d0b300$(E-Mail Removed),
Jimme Quinn Ross <(E-Mail Removed)> made a post then I
commented below
> He did! Well, sort of. The entry I made is now working. I
> need to learn more about DNS. Thanks again for your help!
>
> Jimme


Well, better late than never! Glad we were able to help.
:-)

Ace



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
resolve ip address DaveP Microsoft C# .NET 3 23rd Sep 2007 03:41 AM
Can't resolve own address jaypeerocks@gmail.com Microsoft Windows 2000 DNS 3 25th Apr 2006 04:24 PM
Ip address does not resolve =?Utf-8?B?Y2FybA==?= Microsoft Windows 2000 Networking 2 16th Mar 2006 03:47 PM
Is there a way to resolve attacker's IP address? Nepatsfan Windows XP Security 6 1st Feb 2006 02:41 AM
RIS can't resolve IP address =?Utf-8?B?U3RldmU=?= Microsoft Windows 2000 Deployment 1 27th May 2004 10:01 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:55 PM.