CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-08
philofish philofish is offline
Member
 
Join Date: 2006-01-07
Posts: 32
Rep Power: 0
philofish has an average reputation (10+)
Default Mini DNS on enforcement module

Hello all

as a relative newbie - just passed the CCSA today - pheww
I am not a newbie with regards to firewalls - just ceckpoint but i needed the following answered if possible? -
This is about ISP redundancy and the mini dns server
The enforcement module via GuiDBedit allows you to setup a mini DNS to answer queries for internal services, i.e. HTTP and FTP etc

the docs say register the enforcement point in your ISP's DNS

Quote
Register your domain (e.g. example.com) with
Inform the ISPs of the two addresses of the
queries about the domain example.com.

Does this mean i register the enforcement points as NS records? as they will answer for any A resource record requests for internal systems?

hope this makes sense - maybe i am reading it wrong - but we have a similar setup with our ALTEONS - they are authoritative for internal or sub domains within our LAN
Reply With Quote
  #2 (permalink)  
Old 2006-02-08
philofish philofish is offline
Member
 
Join Date: 2006-01-07
Posts: 32
Rep Power: 0
philofish has an average reputation (10+)
Default Re: Mini DNS on enforcement module

please! someone must know
Reply With Quote
  #3 (permalink)  
Old 2006-02-09
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Mini DNS on enforcement module

It seems that for use ISP redundancy for incoming connections, you should have your own DNS servers in LAN, or rather, all DNS queries should arrive your Firewall-1. So you should have two NS records with IP addresses your Firewall-1 (or some NAT addresses for your DNS servers).
So incoming DNS queries would intercepted by your Firewall-1 and Firewall-1 will return IP by first ISP or by another ISP.

Last edited by kva.kva; 2006-02-09 at 04:32.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:39.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0