Windows Server - Help - External DNS & SMTP relay
Asked By rileymarti
06-Oct-07 10:00 AM

Hi,
I purchased static IP address and cablemodem service and need to install
an external DNS server and an SMTP relay service for an internal email
server. I would like to use Windows 2003 server and turn on the firewall/ICS
that comes with sp2. I looked up information on Technet for securing 2003
and DNS and didn't find any really good documents. What I did find was
general information on Windows firewall/ICS and the general best practices
for DNS I have listed below. Does anyone have any recommendations they can
provide? Thanks.
1) Protect the DNS infrastructure of your organization by utilizing an
internal root and name space.
2) Only the external DNS server is configured with Internet root hints.
3) All internal DNS servers are configured only with the root hints pointing
to the internal DNS servers hosting the root zone for your internal name
space.
4) All DNS servers run on domain controllers with all DNS zones stored in
Active Directory. Active Directory DACLs are utilized to secure
administration of DNS. All DNS servers are configured with NTFS as the file
system.
5) External DNS resolution is only performed by your external DNS server.
The internal DNS servers point to the external DNS server.
6) Internal DNS servers are configured to only permit zone transfers to
specific internal DNS servers.
7) The default setting of cache pollution prevention is enabled.
8) UDP/TCP port 53 is only open between one of your internal DNS servers and
only your external DNS server through a firewall in your DMZ.
9) Only secure dynamic DNS updates are allowed for all zones except for the
top-level and root zones, which do not allow dynamic updates at all.
10) All Internet name resolution is performed using proxy servers and
gateways.
11) Utilize Windows Firewall and create exceptions only for DNS ports TCP
and UDP port 53.
Active Directory
(1)
Linux
(1)
IIS
(1)
DACLs
(1)
SMTP
(1)
Svyatoslav
(1)
Anteaus
(1)
Windows
(1)
Lanwench [MVP - Exchange] replied...
Do you mean you want to host your domains' public DNS in-house? With a cable
modem?
This is a very bad idea. You need two separate nameservers to do this, and
they shouldn't even be on the same IP subnet.
Nor should any of this touch your LAN at all. Your AD must be kept entirely
separated and protected.
I strongly suggest you rethink this.....it's something best left to an
outside service provider who has a datacenter full of powerful redundant
everything.
Even if you decide to host your public DNS like this, I wouldn't recommend
that you put this service on the same box.
The Windows firewall would not be sufficient for this purpose anyway. Sorry
to be a wet blanket, but I think you're asking for a heap o trouble by
trying to do this yourself.
Post in microsoft.public.windows.server.dns for more expert help, but I
suspect you'll be told the same thing by others in there.
rileymarti replied...
Thanks for the reply. I took your advice and posted another message in the
DNS forum.
We definately want our ISP to do as little as possible so we can maintain
control over as much as possible.
I am using private IPs for my internal network and will utilize a second
router with NAT overload and access lists to better protect my internal
network. My internal DNS servers will use an internal name space and my
external DNS server will use a totally separate DNS name space without active
directory.
S. Pidgorny replied...
G'day:
Get externals DNS and mail relay service.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
* http://sl.mvps.org * http://msmvps.com/blogs/sp *
Lanwench [MVP - Exchange] replied...
Cool.
But an ISP isn't the best choice for DNS hosting anyway, generally speaking.
Find a decent hosting company who specializes in doing this sort of thing
and will give you easy management via your own secured control panel.
Again, what you describe indicates you don't have sufficient infrastructure
to do what you wish properly. You need two separate nameservers, and
ideally, they won't even be on the same IP subnet. In fact, using a Windows
box for this is expensive overkill.
You shouldn't use them for anything else - leave your mail relay on another
box, and don't install IIS.
Sorry to sound like the voice of doom, this is the sort of thing that often
seems like a really good idea at the time, but isn't. I'm sure someone in
the DNS group can give you a more exhaustive list of things that can go
wrong than I can.
Anteau replied...
As is so often the case with IT, these recommendations apply to
mega-corporate users and have little relevance to even medium-sized
businesses.
Basically, you want to use a NAT router, and most such routers will provide
DNS forwarding to an ISP's DNS server. This is generally more convenient than
having to set the ISP's DNS addresses on each and every computer.
Some however do not do this reliably, and in that case it may be worthwhile
(on a site with more than just a handful of computers) to set-up a Windows
or Linux server to act as a DNS forwarder. In this case your internal DNS
server should not be made accessible form the internet, so the issues listed
do not in any case arise.
If you are using Active Directory logons you must have an internal DNS
server, anyway.
S. Pidgorny replied...
Since this message is response to my email I need to stress the point:
external secondary DNS and mail relay are inexpensive services available for
masses, and most appropriate for businesses small and medium.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
* http://sl.mvps.org * http://msmvps.com/blogs/sp *
Event id 2042 / 2041 (Directory service) + 12292 / 11 (VSS) Windows Server Hi, I am getting lots of event logs in all 3 domain controllers recently. First of all in Directory service, I am getting these event id 2042 & 2041 as below: { Event Type: Error Event controllers when I try to use backup utility to backup anything: {Backup Status Operation: Backup Active backup destination: File Media name: "Volume 2 Backup.bkf created 10 / 15 / 2008 at 2 me. I really appreciate any reply. Thanks in advance. With best regards, Hemal Windows Server Active Directory Discussions HPSERVER.kbgca.local (1) Volume Shadow Copy Service (1) Active Directory (1) Windows Server (1) RIDNextRID (1) RIDPreviousAllocationPool (1) CheckSDRefDom (1) Dellserver.kbgca.local (1) Hi a252-4c11bf6117e5 Last attempt @ 2008-10-15 18:08:02 failed, result 8614 (0x21a6): The Active Directory cannot replicate with this server because the t ime since the last replication with
Profile: http: / / forums.techarena.in / members / 169993.htm View this thread: http: / / forums.techarena.in / active-directory / 1288776.htm http: / / forums.techarena.in Windows Server Active Directory Discussions Windows Server 2008 R2 (1) Windows Server 2008 (1) Active Directory (1) NetBIOS (1) ProcessingTimeInMilliseconds (1) EventRecordID (1) DNSLint (1) FRSUtil (1) GPResult from GPUpdate and Profile: http: / / forums.techarena.in / members / 169993.htm View this thread: http: / / forums.techarena.in / active-directory / 1288776.htm http: / / forums.techarena.in TBaze, Two quick things: 1) Windows Firewall turned on
are set to 2003. Please help if anyone has suggestions. Thanks so much. Windows Server Active Directory Discussions MYDOMAIN.org.highestCommittedUSN (1) MYDOMAIN.org.isGlobalCatalogReady (1) MYDOMAIN.org.currentTime (1) DC1A.highestCommittedUSN hope that the information above helps you. Have a Nice day. Jorge Silva MCSE, MVP Directory Services Yep, 2003 was pointed to the 2008 DC DNS. I uninstalled DNS from the hope that the information above helps you. Have a Nice day. Jorge Silva MCSE, MVP Directory Services Did you run adprep before introducing the two new 2008 dc's? If you Post the results (Before posting modify anything that might disclose internal info) - - Paul Bergson MVP - Directory Services MCTS, MCT, MCSE, MCSA, Security+, BS CSci 2008, 2003, 2000 (Early Achiever), NT4 http the help so far. I will post back results. best of luck - - Paul Bergson MVP - Directory Services MCTS, MCT, MCSE, MCSA, Security+, BS CSci 2008, 2003, 2000 (Early Achiever), NT4 http v / c / d / e / s:MYDOMAIN.org" Domain Controller Diagnosis Performing initial setup: * Connecting to directory service on server MYDOMAIN.org. MYDOMAIN.org.currentTime = 20090309224141.0Z MYDOMAIN.org.highestCommittedUSN = 2214527 MYDOMAIN pDsInfo Doing initial required tests Testing server: Default-First-Site-Name \ DC1A Starting test: Connectivity * Active Directory LDAP Services Check Failure Analysis: DC1A . . . OK. * Active Directory RPC Services Check . . . . . . . . . . . . . . . . . . . . . . . . . DC1A passed
active directory project Windows Server i have a project coming up soon that i have to figure out how to do. I have very little details on it so far. Converting to active directory copy user profiles from old environment (which i don't know what it is) how Profile: http: / / forums.techarena.in / members / rayc.htm View this thread: http: / / forums.techarena.in / active-directory / 1123687.htm http: / / forums.techarena.in Windows Server Active Directory Discussions Windows XP (1) Windows Server 2003 (1) Active Directory (1) Outlook 2003 (1) Outlook
12-02 10:05:15+1100 620 264 Trying to make out of proc datastore active 2008-12-02 10:05:15+1100 620 264 Out of proc datastore is now active 2008-12-02 10:05:15+1100 620 264 Out of proc datastore is shutting 12-02 10:05:15+1100 712 364 Trying to make out of proc datastore active 2008-12-02 10:05:16+1100 712 364 Out of proc datastore is now active 2008-12-02 10:05:16+1100 712 364 Out of proc datastore is shutting 12-02 10:05:16+1100 992 3e4 Trying to make out of proc datastore active 2008-12-02 10:05:16+1100 620 264 Out of proc datastore is now 2008-12-02 10:05:16+1100 992 3e4 Out of proc datastore is now active 2008-12-02 10:05:16+1100 992 3e4 Out of proc datastore is shutting 12-02 10:35:17+1100 1632 a4 Trying to make out of proc datastore active 2008-12-02 10:35:18+1100 1632 a4 Out of proc datastore is now active 2008-12-02 10:35:18+1100 1632 a4 Out of proc datastore is shutting