How to restrict who can use my DNS Server

J

John

Hi all:

I am fairly sure that this question has been asked many times but here
goes:

I have a Windows 2000 Server running DNS.

I want to configure it so that it only allow my own IP block to use
it, essentially, sorta like Bind "allow-query" statement. Others can
use it to query only domains that I host.

Is there such a thing in the Microsoft DNS World?

Thank you.

-J.
 
A

Ace Fekay [MVP]

In
John said:
Hi all:

I am fairly sure that this question has been asked many times but here
goes:

I have a Windows 2000 Server running DNS.

I want to configure it so that it only allow my own IP block to use
it, essentially, sorta like Bind "allow-query" statement. Others can
use it to query only domains that I host.

Is there such a thing in the Microsoft DNS World?

Thank you.

-J.

Unfortunately, no, not yet. In such a scenario where one would host
internal private and external public data and restrict views accordingly, I
would rather have two separate servers anyway.

--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
MVP Microsoft MVP - Directory Services
Microsoft Certified Trainer

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Infinite Diversities in Infinite Combinations
 
H

Herb Martin

John said:
Hi all:

I am fairly sure that this question has been asked many times but here
goes:

I have a Windows 2000 Server running DNS.

I want to configure it so that it only allow my own IP block to use
it, essentially, sorta like Bind "allow-query" statement. Others can
use it to query only domains that I host.

Is there such a thing in the Microsoft DNS World?

No. You either let them query it fully or you block them
with something like IPSec (or RRAS) filters completely.

BTW: This is one of the several reasons the same DNS
server should NOT be used for your internal resolution and
also for external users.

In fact, in general, your PUBLIC DNS zones should generally
be hosted at the REGISTRAR (especially if you are needing
to double up servers like this.)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top