[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] XP/Samba/Qube3/Frustration
- Subject: Re: [cobalt-users] XP/Samba/Qube3/Frustration
- From: Malcolm McLeary <mmcleary@xxxxxxx>
- Date: Wed Feb 12 12:42:01 2003
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
Hi Jeff,
on 13/2/03 12:44 AM, Jeff Curnow wrote:
>> My suggesstion would be to setup dns on your qube , then point your xp
>> machine to that dns server. ' --Todd
>>
> Wouldn't this open your internal network up to the internet? How do you get
> around the security issues if you set up the DNS for the internal machines
> on the Cube/RAQ and then have that machine exposed to the internet?
Surely the internal machines are sitting behind some form of firewall ...
even a gateway device which supports NAT. If this is the case then none of
the internal machines would be visible to the internet even if someone could
resolve their internal address from their name.
I do this all the time. My primary and Secondary DNS are actually external
to my LAN and I use a Qube3 as my internal DNS. I do not host Primary DNS
for my public address ... only private (i.e. internal) address range.
I have my Qube3 "exposed" to the internet either via port forwarding from an
dedicated device or via ipchains on the 2nd ethernet port. In either case I
don't do the DNS thing for external use.
Cheers, Malcolm