Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Connectivity, Telecommunications & the Internet
Home Forums Register Search Today's Posts Mark Forums Read

Help - External DNS & smtp relay

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 06-Oct-2007, 02:21 PM
rileymartin rileymartin is offline
Posts: 9
Points: 0 rileymartin has no points
Power: 2
None
Join Date: 27 Sep 2007
Help - External DNS & smtp relay

Hi,

I purchased static IP address and cablemodem service and need to install an external DNS server and an SMTP relay service for an internal email server. I would like to use Windows 2003 server and turn on the firewall/ICS that comes with sp2. I looked up information on Technet for securing 2003 and DNS and didn't find any really good documents. What I did find was general information on Windows firewall/ICS and the general best practices for DNS I have listed below. Does anyone have any recommendations they can provide? Thanks.

1) Protect the DNS infrastructure of your organization by utilizing an internal root and name space.
2) Only the external DNS server is configured with Internet root hints.
3) All internal DNS servers are configured only with the root hints pointing to the internal DNS servers hosting the root zone for your internal name space.
4) All DNS servers run on domain controllers with all DNS zones stored in Active Directory. Active Directory DACLs are utilized to secure administration of DNS. All DNS servers are configured with NTFS as the file system.
5) External DNS resolution is only performed by your external DNS server. The internal DNS servers point to the external DNS server.
6) Internal DNS servers are configured to only permit zone transfers to specific internal DNS servers.
7) The default setting of cache pollution prevention is enabled.
UDP/TCP port 53 is only open between one of your internal DNS servers and only your external DNS server through a firewall in your DMZ.
9) Only secure dynamic DNS updates are allowed for all zones except for the top-level and root zones, which do not allow dynamic updates at all.
10) All Internet name resolution is performed using proxy servers and gateways.
11) Utilize Windows Firewall and create exceptions only for DNS ports TCP and UDP port 53.

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Connectivity, Telecommunications & the Internet


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Ethereal Tutorial - Part 3 zebulebu Networking 7 18-Oct-2007 01:11 PM
DNS HELP!!!!!!!!!!!!!!!!! soroush Networking 4 05-Oct-2007 02:30 PM
DNS Islanding zebulebu Networking 3 28-May-2007 01:26 PM
DNS Suffix and NetBios Computer Name stuPeas CIW Certifications 2 15-May-2007 08:39 AM
291 -- Problem in RRAS (Relay Agent) for DHCP 291 aman0999 Network Infrastructure 0 21-Nov-2006 05:03 AM


All times are GMT. The time now is 07:30 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages