I think its generally recommended that you never install DNS on the firewall
itself. They may mention  that you can do it, but I would advise against it.
My rule of thumb is that you never run anything on the firewall that is not
the firewall. I would recommend that you place an external DNS machine on a
DMZ and write specific rules to allow traffic to and from it (and disable
the control properties for DNS).

Will


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of
[EMAIL PROTECTED]
Sent: Thursday, September 28, 2000 9:10 AM
To: [EMAIL PROTECTED]
Subject: [FW1] DNS on firewall gateway



In the Architecture and Administration guide of Firewall-1 Pg 354 there is
some mentioning of dual DNS, where the external DNS can reside on the
firewalled gateway.

Is there any documentation available on how to implement this?

Regards,


Kenneth




============================================================================
====
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
============================================================================
====



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to