DNS server in DMZ or Inside?

Answered Question
Apr 16th, 2007
User Badges:

I'm currently using a Win2003 server as my DMZ on the inside of the network. It's also the server I use as my Domain Controller.


I am reviewing some of my policies and considering some changes. Is it best to have my DNS servers on the Inside or on the DMZ?


Correct Answer by Richard Burts about 10 years 1 week ago

Roland


It is not clear to me from your post what the usage of the DNS server is, and that would influence where you place the server. If the DNS server is only accessed by internal users then placement on the inside is fine. But if the DNS server is also access by anyone outside then I believe that you should place the DNS server in the DMZ.


HTH


Rick

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4.5 (2 ratings)
Loading.
Correct Answer
Richard Burts Mon, 04/16/2007 - 09:36
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Roland


It is not clear to me from your post what the usage of the DNS server is, and that would influence where you place the server. If the DNS server is only accessed by internal users then placement on the inside is fine. But if the DNS server is also access by anyone outside then I believe that you should place the DNS server in the DMZ.


HTH


Rick

rolandshum Mon, 04/16/2007 - 09:52
User Badges:

Rick, the DNS server is only accessed by my internal users. It of course goes out to my ISP to look up when there is a request that isn't it it's tables. I thought it was ok on the Inside network but a bit of confirmation is always nice.


Thanks

Richard Burts Mon, 04/16/2007 - 09:57
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Roland


As long as the DNS server inside initiates the request to outside servers the responses should be allowed through and not represent a security threat.


HTH


Rick

Actions

This Discussion