This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[SOLVED]DNS best practice?

There are two ways to configure DNS:

One way:
- Allowing DNS outgoing for your internal nameservers
- internal nameservers forwarding to ISP-DNS
- ASG pointing to internal nameservers 

Another way:
- ASG forwarding to ISP-nameservers
- "request routing" on ASG for internal domain pointing to internal nameservers
- internal nameservers forwarding to ASG
 
Which way do you use? And why? Which is "officially preferred"?
Both configurations seem working good for me, we run the first alternative on our cluster, the second in branch offices without internal dns (domain dns reachable via site2site-vpn).

Thanks for your ideas!
Thomas



BAlfson's DNS Best Practice's post has been moved to it's own highlighted thread here: https://community.sophos.com/utm-firewall/f/recommended-reads/122972/dns-best-practice
[edited by: FloSupport at 11:12 AM (GMT -7) on 18 Sep 2020]
Parents
  • Good point, BD.  I was just thinking about avoiding .com.  Although there are still a lot of internal domains with .local, given the choice, something like .loc, .home or .office is better.  Check out the post and the Changelog. [;)]

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Good point, BD.  I was just thinking about avoiding .com.  Although there are still a lot of internal domains with .local, given the choice, something like .loc, .home or .office is better.  Check out the post and the Changelog. [;)]

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • I'm having an issue with DNS that I can't seem to figure out.  I would greatly appreciate any and all help!!

    Under DNS > Global > empty
    Forwarders > OpenDNS & Internal DNS (DC) & Use forwarders ISP(unchecked)
    Request Routing > mydomain.com > Internal DNS (DC) & .in-addr.arpa for each subnet > Internal DNS (DC)
    UTM is also joined to domain under SSO

    When I use DNS lookup from UTM I'm able to resolve IP to hostnames and vise versa, but reporting only resolves a few entries.  On my DNS server I have correct records and zones for forward and reverse.  

    Any ideas???

    Thanks,

    James