Professional Documents
Culture Documents
&
Demilitarized Zone
Prepared by: Iyad A. Hawili
SARA-IT (NSEU)
DNS
DOMAIN NAME
SERVICE
SARA-IT (NSEU)
Hostnames
IP Addresses are great for computers
IP address includes information used for
routing.
DNS Hierarchy
edu
com
org
lau aub
lb
com
SARA-IT
SARA-IT (NSEU)
Examples:
SARA-IT.co.uk
SARA-IT.ca
SARA-IT.net
SARA-IT.com
SARA-IT (NSEU)
Domain Name
The domain name for a host is the
sequence of labels that lead from the
host (leaf node in the naming tree) to
the top of the worldwide naming tree.
A domain is a subtree of the worldwide
naming tree.
SARA-IT (NSEU)
SARA-IT (NSEU)
DNS Organization
Distributed Database
The organization that owns a domain name
is responsible for running a DNS server
that can provide the mapping between
hostnames within the domain to IP
addresses.
So - some machine run by SARA-IT is
responsible for everything within the
SARA-IT.ca domain (LBC_ENTERPRISE).
SARA-IT (NSEU)
DNS DB
Authoritative
SARA-IT (NSEU)
Lbc.com
.edu
DNS.edu
DB
DNS
DNSDB
DB
Replicas
10
DNS Servers
Servers handle requests for their
domain directly.
Servers handle requests for other
domains by contacting remote DNS
server(s).
Servers cache external mappings.
SARA-IT (NSEU)
11
DNS Clients
A DNS client is called a resolver.
Windows 2000 workstations has a DNS
client service
Most Unix workstations have the file
/etc/resolv.conf that contains the local
domain and the addresses of DNS
servers for that domain (e.g. stretch &
smartmail).
SARA-IT (NSEU)
12
SARA-IT DNS
13
14
DNS Data
DNS databases contain more than just
hostname-to-address records:
Name server records
Hostname aliases
Mail Exchangers
Host Information
SARA-IT (NSEU)
NS
CNAME
MX
HINFO
15
edu
lau
com
org
lb
co
m
SARA-IT
aub
SARA-IT (NSEU)
16
Server Operation
If a server has no clue about where to
find the address for a hostname, ask
the root server.
The root server will tell you what
nameserver to contact.
A request may get forwarded a few
times.
SARA-IT (NSEU)
17
Recursion
A request can indicate that recursion is
desired - this tells the server to find out
the answer (possibly by contacting
other servers).
If recursion is not requested - the
response may be a list of other name
servers to contact.
SARA-IT (NSEU)
18
SARA-IT (NSEU)
19
Lots more
This is not a complete description !
If interested - look at:
RFC 1034: DNS concepts and facilities.
RFC 1035: DNS implementation and
protocol specification.
SARA-IT (NSEU)
20
DMZ
DIMILITARIZED
ZONE
SARA-IT (NSEU)
21
SNMP
Sniffers
Remote Control Software
Administrative Interfaces (over intended
functional protocols)
SARA-IT (NSEU)
22
Demilitarized Zones
A no mans land analogy
Public services are put on the DMZ
Access restrictions are placed between
External network to DMZ and DMZ to
internal corporate network
SARA-IT (NSEU)
23
24
25
Router
SARA-IT
Corporate Network
Web
SARA-IT (NSEU)
SMSC UMS
26
DNS
INTERNET
Screening
Router
Web
DMZ
Screening
Router
UMS
WAP
DMZ-DNS
SARA-IT (NSEU)
27
SARA-IT (NSEU)
28
SARA-IT (NSEU)
29
SARA-IT (NSEU)
30
SARA-IT (NSEU)
31
SARA-IT (NSEU)
32
Thanks
SARA-IT (NSEU)
33