DNS in the LAN should be cautious

xiaoxiao2021-03-06  103

Due to the business office needs, the author deploys the DNS server in the LAN, and the DNS server address parameters on all clients are set to the IP address of the server. And a new domain called "RTJ.NET" is also created in the DNS server, which is required to access the internal website needs.

But tested, users can access the intranet of the enterprise normally, but there is a problem when accessing websites on the Internet. After the author of the client's DNS server address is modified to the IP address of the public DNS server, you can access the website on the Internet, but you can't access the internal website. However, in order to save funds, the "RTJ.NET" field does not register on the public DNS server, and can only be parsed by the internal DNS server in the enterprise network, is there a two full beauty approach?

analysis

DNS (Domain Name Server) is a huge distributed database that provides information on a specified domain through a domain name server to implement a domain name, and the domain name server is responsible for converting domain names to an IP address. It is impossible to place all domain name information in the Internet in the same computer, so the DNS system uses a tree structure to store the domain name information of different hierarchical domains in different domain name servers, and the highest layer is the root server.

To analyze the name

Www.fysz.net domain name, client first to contact the local domain server, if this domain name is not checked, the local domain name server sends a request to the root domain server, query www.fyssz.net IP address, root domain The server discovers that the domain name does not belong to its own jurisdiction, but a domain under NET, which will notify the domain name server to contact the NET domain to get more information, and send a local domain server all NET domain name servers. Address list. Then, the local domain name server will continue to send a parsing request to these servers until a domain name server belongs to the FYSSZ.NET domain and returns www.fyssz.net's IP address information to the customer.

Since the author creates root domain and NET domain in the DNS server in the local area network, when the DNS server receives a domain name that cannot be parsed, it will be incorrectly considering the root domain server, and the real root domain server in the Internet can not be found. Therefore, there will be a problem that the client cannot use the domain name to access the website.

Solution

First remove the root domain, NET domain, and RTJ.NET domain in the DNS server, and then recreate an RTJ.NET domain, create this domain to allow clients to access the company's internal website. At the same time, in addition to the domains necessary for the internal website, you should do as little as possible, prevent DNS server errors from resolving domain names or unable to resolve.

转载请注明原文地址:https://www.9cbs.com/read-104019.html

New Post(0)